PT-2024-27819 · Mastodon · Mastodon

Clearlyclaire

·

Published

2024-07-05

·

Updated

2024-07-09

·

CVE-2024-37903

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Mastodon versions 2.6.0 through 4.1.17 Mastodon versions 4.2.0 through 4.2.9
Description Mastodon is a self-hosted, federated microblogging platform. By crafting specific activities, an attacker can extend the audience of a post they do not own to other Mastodon users on a target server, thus gaining access to the contents of a post not intended for them.
Recommendations For Mastodon versions 2.6.0 through 4.1.17, update to version 4.1.18 or later. For Mastodon versions 4.2.0 through 4.2.9, update to version 4.2.10 or later.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

BIT-MASTODON-2024-37903
CVE-2024-37903
GHSA-XJVF-FM67-4QC3

Affected Products

Mastodon