Vulnerability Description
Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authentication. Starting in version 2.5.0 and prior to versions 3.5.8, 4.0.4, and 4.1.2, the LDAP query made during login is insecure and the attacker can perform LDAP injection attack to leak arbitrary attributes from LDAP database. This issue is fixed in versions 3.5.8, 4.0.4, and 4.1.2.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Joinmastodon | Mastodon | >= 2.5.0, < 3.5.8 |
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2023/07/06/6
- https://github.com/mastodon/mastodon/blob/94cbd808b5b3e7999c7e77dc724b7e8c9dd2bdProduct
- https://github.com/mastodon/mastodon/blob/94cbd808b5b3e7999c7e77dc724b7e8c9dd2bdProduct
- https://github.com/mastodon/mastodon/pull/24379Patch
- https://github.com/mastodon/mastodon/releases/tag/v3.5.8Release Notes
- https://github.com/mastodon/mastodon/releases/tag/v4.0.4Release Notes
- https://github.com/mastodon/mastodon/releases/tag/v4.1.2Release Notes
- https://github.com/mastodon/mastodon/security/advisories/GHSA-38g9-pfm9-gfqvExploitVendor Advisory
- http://www.openwall.com/lists/oss-security/2023/07/06/6
- https://github.com/mastodon/mastodon/blob/94cbd808b5b3e7999c7e77dc724b7e8c9dd2bdProduct
- https://github.com/mastodon/mastodon/blob/94cbd808b5b3e7999c7e77dc724b7e8c9dd2bdProduct
- https://github.com/mastodon/mastodon/pull/24379Patch
- https://github.com/mastodon/mastodon/releases/tag/v3.5.8Release Notes
- https://github.com/mastodon/mastodon/releases/tag/v4.0.4Release Notes
- https://github.com/mastodon/mastodon/releases/tag/v4.1.2Release Notes
FAQ
What is CVE-2023-28853?
CVE-2023-28853 is a vulnerability with a CVSS score of 7.7 (HIGH). Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authentication. Starting in version 2.5.0 and prior to versions 3.5.8, 4.0.4, and 4...
How severe is CVE-2023-28853?
CVE-2023-28853 has been rated HIGH with a CVSS base score of 7.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-28853?
Check the references section above for vendor advisories and patch information. Affected products include: Joinmastodon Mastodon.