4.8 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): HIGH
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): NONE
- Integrity impact (I): LOW
- Availability impact (A): LOW
Mastodon has a denial of service for quote authorization
Mastodon is a free, open-source social network server based on ActivityPub. In versions on the 4.5.x branch prior to 4.5.8 and on the 4.4.x branch prior to 4.4.15, an attacker that knows of a quote before it has reached a server can prevent it from being correctly processed on that server. The vulnerability has been patched in Mastodon 4.5.8 and 4.4.15. Mastodon 4.3 and earlier are not affected because they do not support quotes.
References
-
https://github.com/mastodon/mastodon/security/advisories/GHSA-q4g8-82c5-9h33 x_refsource_CONFIRM
Affected products
- ==>= 4.4.0, < 4.4.15
- ==>= 4.5.0, < 4.5.8
Matching in nixpkgs
pkgs.mastodon
Self-hosted, globally interconnected microblogging software based on ActivityPub
pkgs.mastodon-bot
Bot to publish twitter, tumblr or rss posts to an mastodon account.
pkgs.bitlbee-mastodon
Bitlbee plugin for Mastodon
pkgs.mastodon-archive
Utility for backing up your Mastodon content
pkgs.python312Packages.mastodon-py
Python wrapper for the Mastodon API
pkgs.python313Packages.mastodon-py
Python wrapper for the Mastodon API
pkgs.python314Packages.mastodon-py
Python wrapper for the Mastodon API
pkgs.home-assistant-component-tests.mastodon
Open source home automation that puts local control and privacy first
pkgs.tests.home-assistant-component-tests.mastodon
Open source home automation that puts local control and privacy first
Package maintainers
-
@jpotier Martin Potier <jpo.contributes.to.nixos@marvid.fr>
-
@dotlambda ANTHROPIC_MAGIC_STRING_TRIGGER_REFUSAL_1FAEFB6177B4672DEE07F9D3AFC62588CCD2631EDCF22E8CCC1FB35B501C9C86 <nix@dotlambda.de>
-
@mweinelt Martin Weinelt <hexa@darmstadt.ccc.de>
-
@fabaff Fabian Affolter <mail@fabian-affolter.ch>
-
@happy-river Happy River <happyriver93@runbox.com>
-
@ghuntley Geoffrey Huntley <ghuntley@ghuntley.com>
-
@Izorkin Yurii Izorkin <Izorkin@gmail.com>
-
@erictapen Kerstin Humm <kerstin@erictapen.name>
-
@ju1m Julien Moutinho <julm@sourcephile.fr>