PT-2024-27819 · Mastodon · Mastodon

·

CVE-2024-37903

·

Published

2024-07-05

·

Updated

2024-07-09

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Mastodon versions 2.6.0 through 4.1.17 Mastodon versions 4.2.0 through 4.2.9
Description Mastodon is a self-hosted, federated microblogging platform. By crafting specific activities, an attacker can extend the audience of a post they do not own to other Mastodon users on a target server, thus gaining access to the contents of a post not intended for them.
Recommendations For Mastodon versions 2.6.0 through 4.1.17, update to version 4.1.18 or later. For Mastodon versions 4.2.0 through 4.2.9, update to version 4.2.10 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-MASTODON-2024-37903
CVE-2024-37903
GHSA-XJVF-FM67-4QC3

Affected Products

Mastodon