PT-2024-35389 · Misskey · Misskey
Warriordog
·
Published
2024-12-18
·
Updated
2025-11-26
·
CVE-2024-52592
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Misskey versions prior to 2024.11.0-alpha.3
Description
Misskey is an open source, federated social media platform. In affected versions, missing validation in
ApInboxService.update allows an attacker to modify the result of polls belonging to another user. No authentication is required, except for a valid signature from any actor on any remote instance. Vulnerable Misskey instances will accept spoofed updates for remote polls. Local polls are unaffected.Recommendations
For versions prior to 2024.11.0-alpha.3, update to version 2024.11.0-alpha.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the
ApInboxService.update function until a patch is available. Avoid accepting updates for remote polls from untrusted sources until the issue is resolved.Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Misskey