CVE-2023-42451
19.09.2023, 16:15
Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 3.5.14, 4.0.10, 4.1.8, and 4.2.0-rc2, under certain circumstances, attackers can exploit a flaw in domain name normalization to spoof domains they do not own. Versions 3.5.14, 4.0.10, 4.1.8, and 4.2.0-rc2 contain a patch for this issue.Enginsight
Vendor | Product | Version |
---|---|---|
joinmastodon | mastodon | 𝑥 < 3.5.14 |
joinmastodon | mastodon | 4.0.0 ≤ 𝑥 < 4.0.10 |
joinmastodon | mastodon | 4.1.0 ≤ 𝑥 < 4.1.8 |
joinmastodon | mastodon | 4.2.0:beta1 |
joinmastodon | mastodon | 4.2.0:beta2 |
joinmastodon | mastodon | 4.2.0:beta3 |
joinmastodon | mastodon | 4.2.0:rc1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References