U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-25623

Change History

New CVE Received from GitHub, Inc. 2/19/2024 11:15:51 AM

Action Type Old Value New Value
Added Description

								
							
							
						
Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.2.7, 4.1.15, 4.0.15, and 3.5.19, when fetching remote statuses, Mastodon doesn't check that the response from the remote server has a `Content-Type` header value of the Activity Streams media type, which allows a threat actor to upload a crafted Activity Streams document to a remote server and make a Mastodon server fetch it, if the remote server accepts arbitrary user uploads. The vulnerability allows a threat actor to impersonate an account on a remote server that satisfies all of the following properties: allows the attacker to register an account; accepts arbitrary user-uploaded documents and places them on the same domain as the ActivityPub actors; and serves user-uploaded document in response to requests with an `Accept` header value of the Activity Streams media type. Versions 4.2.7, 4.1.15, 4.0.15, and 3.5.19 contain a fix for this issue.
Added CVSS V3.1

								
							
							
						
GitHub, Inc. AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N
Added CWE

								
							
							
						
GitHub, Inc. CWE-434
Added Reference

								
							
							
						
GitHub, Inc. https://github.com/mastodon/mastodon/commit/9fee5e852669e26f970e278021302e1a203fc022 [No types assigned]
Added Reference

								
							
							
						
GitHub, Inc. https://github.com/mastodon/mastodon/security/advisories/GHSA-jhrq-qvrm-qr36 [No types assigned]