← Back

CVE-2023-42450

nvd nist
Published: Sep 19, 2023Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 4.2.0-beta1 and prior to version 4.2.0-rc2, by crafting specific input, attackers can inject arbitrary data into HTTP requests issued by Mastodon. This can be used to perform confused deputy attacks if the server configuration includes `ALLOWED_PRIVATE_ADDRESSES` to allow access to local exploitable services. Version 4.2.0-rc2 has a patch for the issue.

Affected (4)

1 product
Mastodon
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Joinmastodon
Version 4.2.0 beta1
Version 4.2.0 beta2
Version 4.2.0 beta3
Version 4.2.0 rc1

References (4)

Timeline

No history available yet.