Vulnerability Description
Mastodon is a free, open-source social network server based on ActivityPub. When performing outgoing HTTP queries, Mastodon sets a timeout on individual read operations. Prior to versions 3.5.9, 4.0.5, and 4.1.3, a malicious server can indefinitely extend the duration of the response through slowloris-type attacks. This vulnerability can be used to keep all Mastodon workers busy for an extended duration of time, leading to the server becoming unresponsive. Versions 3.5.9, 4.0.5, and 4.1.3 contain a patch for this issue.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Joinmastodon | Mastodon | < 3.5.9 |
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2023/07/06/7Mailing List
- https://github.com/mastodon/mastodon/commit/c5929798bf7e56cc2c79b15bed0c4692ded3PatchThird Party Advisory
- https://github.com/mastodon/mastodon/releases/tag/v3.5.9Third Party Advisory
- https://github.com/mastodon/mastodon/releases/tag/v4.0.5Third Party Advisory
- https://github.com/mastodon/mastodon/releases/tag/v4.1.3Third Party Advisory
- https://github.com/mastodon/mastodon/security/advisories/GHSA-9pxv-6qvf-pjwcThird Party Advisory
- http://www.openwall.com/lists/oss-security/2023/07/06/7Mailing List
- https://github.com/mastodon/mastodon/commit/c5929798bf7e56cc2c79b15bed0c4692ded3PatchThird Party Advisory
- https://github.com/mastodon/mastodon/releases/tag/v3.5.9Third Party Advisory
- https://github.com/mastodon/mastodon/releases/tag/v4.0.5Third Party Advisory
- https://github.com/mastodon/mastodon/releases/tag/v4.1.3Third Party Advisory
- https://github.com/mastodon/mastodon/security/advisories/GHSA-9pxv-6qvf-pjwcThird Party Advisory
FAQ
What is CVE-2023-36461?
CVE-2023-36461 is a vulnerability with a CVSS score of 7.5 (HIGH). Mastodon is a free, open-source social network server based on ActivityPub. When performing outgoing HTTP queries, Mastodon sets a timeout on individual read operations. Prior to versions 3.5.9, 4.0.5...
How severe is CVE-2023-36461?
CVE-2023-36461 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-36461?
Check the references section above for vendor advisories and patch information. Affected products include: Joinmastodon Mastodon.