Pixelfed is an open source photo sharing platform. When processing requests authorization was improperly and insufficiently checked, allowing attackers to access far more functionality than users intended, including to the administrative and moderator functionality of the Pixelfed server. This vulnerability affects every version of Pixelfed between v0.10.4 and v0.11.9, inclusive. A proof of concept of this vulnerability exists. This vulnerability affects every local user of a Pixelfed server, and can potentially affect the servers' ability to federate. Some user interaction is required to setup the conditions to be able to exercise the vulnerability, but the attacker could conduct this attack time-delayed manner, where user interaction is not actively required. This vulnerability has been addressed in version 0.11.11. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0638 | Pixelfed is an open source photo sharing platform. When processing requests authorization was improperly and insufficiently checked, allowing attackers to access far more functionality than users intended, including to the administrative and moderator functionality of the Pixelfed server. This vulnerability affects every version of Pixelfed between v0.10.4 and v0.11.9, inclusive. A proof of concept of this vulnerability exists. This vulnerability affects every local user of a Pixelfed server, and can potentially affect the servers' ability to federate. Some user interaction is required to setup the conditions to be able to exercise the vulnerability, but the attacker could conduct this attack time-delayed manner, where user interaction is not actively required. This vulnerability has been addressed in version 0.11.11. Users are advised to upgrade. There are no known workarounds for this vulnerability. |
Github GHSA |
GHSA-gccq-h3xj-jgvf | Pixelfed doesn't check OAuth Scopes in API routes, giving elevated permissions |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 07 May 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 11 Oct 2024 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pixelfed
Pixelfed pixelfed |
|
| CPEs | cpe:2.3:a:pixelfed:pixelfed:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Pixelfed
Pixelfed pixelfed |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-05-07T21:03:35.510Z
Reserved: 2024-02-05T14:14:46.378Z
Link: CVE-2024-25108
Updated: 2024-08-01T23:36:21.706Z
Status : Modified
Published: 2024-02-12T20:15:08.590
Modified: 2024-11-21T09:00:16.267
Link: CVE-2024-25108
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA