CVE-2023-42451

Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 3.5.14, 4.0.10, 4.1.8, and 4.2.0-rc2, under certain circumstances, attackers can exploit a flaw in domain name normalization to spoof domains they do not own. Versions 3.5.14, 4.0.10, 4.1.8, and 4.2.0-rc2 contain a patch for this issue.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.4 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
GitHub_MCNA
7.4 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 39%
VendorProductVersion
joinmastodonmastodon
𝑥
< 3.5.14
joinmastodonmastodon
4.0.0 ≤
𝑥
< 4.0.10
joinmastodonmastodon
4.1.0 ≤
𝑥
< 4.1.8
joinmastodonmastodon
4.2.0:beta1
joinmastodonmastodon
4.2.0:beta2
joinmastodonmastodon
4.2.0:beta3
joinmastodonmastodon
4.2.0:rc1
𝑥
= Vulnerable software versions