← Back

CVE-2024-32983

nvd nist
Published: Jun 3, 2024Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

Misskey is an open source, decentralized microblogging platform. Misskey doesn't perform proper normalization on the JSON structures of incoming signed ActivityPub activity objects before processing them, allowing threat actors to spoof the contents of signed activities and impersonate the authors of the original activities. This vulnerability is fixed in 2024.5.0.

Affected (1)

Products: Misskey: Misskey
1 product
Misskey
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 2024.5.0

References (4)

Timeline

No history available yet.