PT-2024-35388 · Misskey · Misskey
Warriordog
·
Published
2024-12-18
·
Updated
2025-03-11
·
CVE-2024-52591
CVSS v3.1
9.3
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Misskey versions prior to 2024.11.0-alpha.3
Description
Misskey is an open source, federated social media platform. In affected versions, missing validation in
ApRequestService.signedGet and HttpRequestService.getActivityJson allows an attacker to create fake user profiles and forged notes. The spoofed users will appear to be from a different instance than the one where they actually exist, and the forged notes will appear to be posted by a different user. Vulnerable Misskey instances will accept the spoofed objects as valid, allowing an attacker to impersonate other users and instances. The attacker retains full control of the spoofed user / note and can interact like a real account.Recommendations
To resolve the issue, update to version 2024.11.0-alpha.3 or later. As a temporary workaround, consider restricting interactions with unverified user profiles and notes until the update is applied. There are no known workarounds for this vulnerability, so upgrading to the fixed version is the recommended course of action.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Misskey