← Back

CVE-2024-23832

nvd nist
Published: Feb 1, 2024Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authentication. Due to insufficient origin validation in all Mastodon, attackers can impersonate and take over any remote account. Every Mastodon version prior to 3.5.17 is vulnerable, as well as 4.0.x versions prior to 4.0.13, 4.1.x version prior to 4.1.13, and 4.2.x versions prior to 4.2.5.

Affected (4)

1 product
Mastodon
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Joinmastodon
Before 3.5.17
From 4.0.0 to 4.0.13
From 4.1.0 to 4.1.13
From 4.2.0 to 4.2.5

References (6)

Source: security-advisories@github.com
Mailing ListPatch
Source: security-advisories@github.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.