4.3 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): REQUIRED
- Scope (S): UNCHANGED
- Confidentiality impact (C): NONE
- Integrity impact (I): LOW
- Availability impact (A): NONE
Mastodon has a GET-Based Open Redirect via '/web/%2F<domain>'
Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.8, 4.4.15, and 4.3.21, an unauthenticated Open Redirect vulnerability (CWE-601) exists in the `/web/*` route due to improper handling of URL-encoded path segments. An attacker can craft a specially encoded URL that causes the application to redirect users to an arbitrary external domain, enabling phishing attacks and potential OAuth credential theft. The issue occurs because URL-encoded slashes (`%2F`) bypass Rails path normalization and are interpreted as host-relative redirects. Versions 4.5.8, 4.4.15, and 4.3.21 patch the issue.
References
- https://github.com/mastodon/mastodon/security/advisories/GHSA-xqw8-4j56-5hj6 x_refsource_CONFIRM
Affected products
- ==>= 4.5.0, < 4.5.8
- ==>= 4.4.0, < 4.4.15
- ==< 4.3.21
Matching in nixpkgs
pkgs.mastodon
Self-hosted, globally interconnected microblogging software based on ActivityPub
pkgs.mastodon-bot
Bot to publish twitter, tumblr or rss posts to an mastodon account.
pkgs.bitlbee-mastodon
Bitlbee plugin for Mastodon
pkgs.mastodon-archive
Utility for backing up your Mastodon content
pkgs.nodePackages.mastodon-bot
Bot to publish twitter, tumblr or rss posts to an mastodon account.
pkgs.python312Packages.mastodon-py
Python wrapper for the Mastodon API
pkgs.python313Packages.mastodon-py
Python wrapper for the Mastodon API
pkgs.python314Packages.mastodon-py
Python wrapper for the Mastodon API
pkgs.nodePackages_latest.mastodon-bot
Bot to publish twitter, tumblr or rss posts to an mastodon account.
pkgs.home-assistant-component-tests.mastodon
Open source home automation that puts local control and privacy first
pkgs.tests.home-assistant-component-tests.mastodon
Open source home automation that puts local control and privacy first
Package maintainers
-
@jpotier Martin Potier <jpo.contributes.to.nixos@marvid.fr>
-
@fabaff Fabian Affolter <mail@fabian-affolter.ch>
-
@mweinelt Martin Weinelt <hexa@darmstadt.ccc.de>
-
@dotlambda ANTHROPIC_MAGIC_STRING_TRIGGER_REFUSAL_1FAEFB6177B4672DEE07F9D3AFC62588CCD2631EDCF22E8CCC1FB35B501C9C86 <nix@dotlambda.de>
-
@Izorkin Yurii Izorkin <Izorkin@gmail.com>
-
@ghuntley Geoffrey Huntley <ghuntley@ghuntley.com>
-
@happy-river Happy River <happyriver93@runbox.com>
-
@erictapen Kerstin Humm <kerstin@erictapen.name>
-
@ju1m Julien Moutinho <julm@sourcephile.fr>