PT-2026-2182 · Mastodon · Mastodon
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Mastodon versions 4.3 through 4.3.16
Mastodon versions 4.4 through 4.4.10
Mastodon versions 4.5 through 4.5.3
Description
Mastodon is a free, open-source social network server based on ActivityPub. A flaw exists in the code handling the download of lists of severed relationships for a particular event. This code does not verify the ownership of the list before returning the lost relationships. Consequently, any registered local user can access lists of lost followers and followed users resulting from any severance event, effectively enumerating severance events across the system. The leaked information does not include the name of the account that lost follows and followers.
Recommendations
Update Mastodon to version 4.3.17 or later.
Update Mastodon to version 4.4.11 or later.
Update Mastodon to version 4.5.4 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mastodon