PT-2026-73372 · Bitnami · Mastodon
Published
2026-08-17
·
Updated
2026-08-17
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Mastodon is a free, open-source social network server based on ActivityPub. From 4.6.0 until 4.6.4 and 4.7.0, any logged-in local user could use the show action in app/controllers/admin/collections controller.rb to access personally identifying information about another local user in a collection because the controller used the general collection policy instead of the admin collection policy namespace. The exposed data included the other user's current email address and last-used IP address. This issue is fixed in versions 4.6.4 and 4.7.0.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mastodon