PT-2023-19794 · Misskey · Misskey

Ry0Tak

·

Published

2023-02-22

·

Updated

2023-03-03

·

CVE-2023-24810

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Misskey versions prior to 13.3.1
Description The issue arises from insufficient validation of the redirect URL during miauth authentication, allowing arbitrary JavaScript execution when a user allows the link. This can be exploited when users authenticate untrusted apps.
Recommendations For versions prior to 13.3.1, upgrade to version 13.3.1 to resolve the issue. As a temporary workaround for users unable to upgrade, do not allow authentication of untrusted apps.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-24810
GHSA-CC6R-CHGR-8R5M

Affected Products

Misskey