Vulnerability Description
The Android App 'Tootdon for Mastodon' version 3.4.1 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mastodon-Tootdon | Tootdon For Mastodon | <= 3.4.1 |
Related Weaknesses (CWE)
References
- http://blog.mastodon-tootdon.com/entry/2019/05/20/204019Vendor Advisory
- https://jvn.jp/en/jp/JVN57806517/index.htmlThird Party Advisory
- http://blog.mastodon-tootdon.com/entry/2019/05/20/204019Vendor Advisory
- https://jvn.jp/en/jp/JVN57806517/index.htmlThird Party Advisory
FAQ
What is CVE-2019-5961?
CVE-2019-5961 is a vulnerability with a CVSS score of 7.4 (HIGH). The Android App 'Tootdon for Mastodon' version 3.4.1 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive inf...
How severe is CVE-2019-5961?
CVE-2019-5961 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-5961?
Check the references section above for vendor advisories and patch information. Affected products include: Mastodon-Tootdon Tootdon For Mastodon.