← Back

CVE-2023-42451

nvd nist
Published: Sep 19, 2023Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 3.5.14, 4.0.10, 4.1.8, and 4.2.0-rc2, under certain circumstances, attackers can exploit a flaw in domain name normalization to spoof domains they do not own. Versions 3.5.14, 4.0.10, 4.1.8, and 4.2.0-rc2 contain a patch for this issue.

Affected (7)

1 product
Mastodon
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Joinmastodon
Before 3.5.14
From 4.0.0 to 4.0.10
From 4.1.0 to 4.1.8
Version 4.2.0 beta1
Version 4.2.0 beta2
Version 4.2.0 beta3
Version 4.2.0 rc1

References (4)

Timeline

No history available yet.