Vulnerability Description
Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 3.5.14, 4.0.10, 4.1.8, and 4.2.0-rc2, under certain circumstances, attackers can exploit a flaw in domain name normalization to spoof domains they do not own. Versions 3.5.14, 4.0.10, 4.1.8, and 4.2.0-rc2 contain a patch for this issue.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Joinmastodon | Mastodon | < 3.5.14 |
Related Weaknesses (CWE)
References
- https://github.com/mastodon/mastodon/commit/eeab3560fc0516070b3fb97e089b15ecab19Patch
- https://github.com/mastodon/mastodon/security/advisories/GHSA-v3xf-c9qf-j667Vendor Advisory
- https://github.com/mastodon/mastodon/commit/eeab3560fc0516070b3fb97e089b15ecab19Patch
- https://github.com/mastodon/mastodon/security/advisories/GHSA-v3xf-c9qf-j667Vendor Advisory
FAQ
What is CVE-2023-42451?
CVE-2023-42451 is a vulnerability with a CVSS score of 7.4 (HIGH). Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 3.5.14, 4.0.10, 4.1.8, and 4.2.0-rc2, under certain circumstances, attackers can exploit a flaw in domain ...
How severe is CVE-2023-42451?
CVE-2023-42451 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-42451?
Check the references section above for vendor advisories and patch information. Affected products include: Joinmastodon Mastodon.