PT-2023-8743 · Mastodon · Mastodon
Cure53
·
Published
2023-07-06
·
Updated
2024-03-06
·
CVE-2023-36460
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Mastodon versions 3.5.0 through 3.5.8
Mastodon versions 4.0.0 through 4.0.4
Mastodon versions 4.1.0 through 4.1.2
Description
The issue arises from a flaw in the media processing code, allowing attackers to create arbitrary files at any location using carefully crafted media files. This can lead to Denial of Service and arbitrary Remote Code Execution. The vulnerability is caused by an error in input validation when handling directory traversal sequences.
Recommendations
For Mastodon versions 3.5.0 through 3.5.8, update to version 3.5.9 or later.
For Mastodon versions 4.0.0 through 4.0.4, update to version 4.0.5 or later.
For Mastodon versions 4.1.0 through 4.1.2, update to version 4.1.3 or later.
As a temporary workaround, consider restricting access to the media processing code until a patch is applied. Avoid using the media file handler component until the issue is resolved.
Exploit
Fix
RCE
DoS
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mastodon