Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authentication. Due to insufficient origin validation in all Mastodon, attackers can impersonate and take over any remote account. Every Mastodon version prior to 3.5.17 is vulnerable, as well as 4.0.x versions prior to 4.0.13, 4.1.x version prior to 4.1.13, and 4.2.x versions prior to 4.2.5.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-02-01T16:18:03.528Z

Updated: 2024-08-01T23:13:08.481Z

Reserved: 2024-01-22T22:23:54.340Z

Link: CVE-2024-23832

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2024-02-01T17:15:10.677

Modified: 2024-02-09T20:21:45.317

Link: CVE-2024-23832

cve-icon Redhat

No data.