4.8 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): HIGH
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): NONE
- Integrity impact (I): LOW
- Availability impact (A): LOW
Mastodon has a denial of service for quote authorization
Mastodon is a free, open-source social network server based on ActivityPub. In versions on the 4.5.x branch prior to 4.5.8 and on the 4.4.x branch prior to 4.4.15, an attacker that knows of a quote before it has reached a server can prevent it from being correctly processed on that server. The vulnerability has been patched in Mastodon 4.5.8 and 4.4.15. Mastodon 4.3 and earlier are not affected because they do not support quotes.
References
- https://github.com/mastodon/mastodon/security/advisories/GHSA-q4g8-82c5-9h33 x_refsource_CONFIRM
Affected products
- ==>= 4.5.0, < 4.5.8
- ==>= 4.4.0, < 4.4.15
Matching in nixpkgs
pkgs.mastodon
Self-hosted, globally interconnected microblogging software based on ActivityPub
pkgs.mastodon-bot
Bot to publish twitter, tumblr or rss posts to an mastodon account.
pkgs.bitlbee-mastodon
Bitlbee plugin for Mastodon
pkgs.mastodon-archive
Utility for backing up your Mastodon content
pkgs.nodePackages.mastodon-bot
Bot to publish twitter, tumblr or rss posts to an mastodon account.
pkgs.python312Packages.mastodon-py
Python wrapper for the Mastodon API
pkgs.python313Packages.mastodon-py
Python wrapper for the Mastodon API
pkgs.python314Packages.mastodon-py
Python wrapper for the Mastodon API
pkgs.nodePackages_latest.mastodon-bot
Bot to publish twitter, tumblr or rss posts to an mastodon account.
pkgs.home-assistant-component-tests.mastodon
Open source home automation that puts local control and privacy first
pkgs.tests.home-assistant-component-tests.mastodon
Open source home automation that puts local control and privacy first
Package maintainers
-
@jpotier Martin Potier <jpo.contributes.to.nixos@marvid.fr>
-
@fabaff Fabian Affolter <mail@fabian-affolter.ch>
-
@mweinelt Martin Weinelt <hexa@darmstadt.ccc.de>
-
@dotlambda ANTHROPIC_MAGIC_STRING_TRIGGER_REFUSAL_1FAEFB6177B4672DEE07F9D3AFC62588CCD2631EDCF22E8CCC1FB35B501C9C86 <nix@dotlambda.de>
-
@Izorkin Yurii Izorkin <Izorkin@gmail.com>
-
@ghuntley Geoffrey Huntley <ghuntley@ghuntley.com>
-
@happy-river Happy River <happyriver93@runbox.com>
-
@erictapen Kerstin Humm <kerstin@erictapen.name>
-
@ju1m Julien Moutinho <julm@sourcephile.fr>