Nixpkgs Security Tracker

Login with GitHub

Suggestions search

With package: home-assistant-component-tests.mastodon

Found 5 matching suggestions

Untriaged
created 2 weeks, 6 days ago
Mastodon may allow a remote suspension bypass

Mastodon is a free, open-source social network server based on ActivityPub. Mastodon allows server administrators to suspend remote users to prevent interactions. However, some logic errors allow already-known posts from such suspended users to appear in timelines if boosted. Furthermore, under certain circumstances, previously-unknown posts from suspended users can be processed. This issue allows old posts from suspended users to occasionally end up on timelines on all Mastodon versions. Additionally, on Mastodon versions from v4.5.0 to v4.5.4, v4.4.5 to v4.4.11, v4.3.13 to v4.3.17, and v4.2.26 to v4.2.29, remote suspended users can partially bypass the suspension to get new posts in. Mastodon versions v4.5.5, v4.4.12, v4.3.18 are patched.

Affected products

mastodon
  • ==>= 4.4.0, < 4.4.12
  • ==< 4.3.18
  • ==>= 4.5.0, < 4.5.5

Matching in nixpkgs

Untriaged
created 2 weeks, 6 days ago
Mastodon missing length limits on list names, filter names, and filter keywords

Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.5, 4.4.12, and 4.3.18, the server does not enforce a maximum length for the names of lists or filters, or for filter keywords, allowing any user to set an arbitrarily long string as the name or keyword. Any local user can abuse the list or filter fields to cause disproportionate storage and computing resource usage. They can additionally cause their own web interface to be unusable, although they must intentionally do this to themselves or unknowingly approve a malicious API client. Mastodon versions v4.5.5, v4.4.12, v4.3.18 are patched.

Affected products

mastodon
  • ==>= 4.4.0, < 4.4.12
  • ==< 4.3.18
  • ==>= 4.5.0, < 4.5.5

Matching in nixpkgs

Untriaged
created 2 weeks, 6 days ago
Mastodon vulnerable to Denial of Service from a single post (client/server)

Mastodon is a free, open-source social network server based on ActivityPub. Mastodon versions before v4.3.18, v4.4.12, and v4.5.5 do not have a limit on the maximum number of poll options for remote posts, allowing attackers to create polls with a very large amount of options, greatly increasing resource consumption. Depending on the number of poll options, an attacker can cause disproportionate resource usage in both Mastodon servers and clients, potentially causing Denial of Service either server-side or client-side. Mastodon versions v4.5.5, v4.4.12, v4.3.18 are patched.

Affected products

mastodon
  • ==>= 4.4.0, < 4.4.12
  • ==< 4.3.18
  • ==>= 4.5.0, < 4.5.5

Matching in nixpkgs

Untriaged
created 2 weeks, 6 days ago
Mastodon has insufficient access control to push notification settings

Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.5, 4.4.12, and 4.3.18, an insecure direct object reference in the web push subscription update endpoint lets any authenticated user update another user's push subscription by guessing or obtaining the numeric subscription id. This can be used to disrupt push notifications for other users and also leaks the web push subscription endpoint. Any user with a web push subscription is impacted, because another authenticated user can tamper with their push subscription settings if they can guess or obtain the subscription id. This allows an attacker to disrupt push notifications by changing the policy (whether to filter notifications from non-followers or non-followed users) and subscribed notification types of their victims. Additionally, the endpoint returns the subscription object, which includes the push notification endpoint for this subscription, but not its keypair. Mastodon versions v4.5.5, v4.4.12, v4.3.18 are patched.

Affected products

mastodon
  • ==>= 4.4.0, < 4.4.12
  • ==< 4.3.18
  • ==>= 4.5.0, < 4.5.5

Matching in nixpkgs

Untriaged
created 4 months, 3 weeks ago
Registry-support: decompress can delete files outside scope via relative paths

A vulnerability was found in the decompression function of registry-support. This issue can be triggered by an unauthenticated remote attacker when tricking a user into opening a specially modified .tar archive, leading to the cleanup process following relative paths to overwrite or delete files outside the intended scope.

Affected products

odo
registry-support
  • ==1.16.2
openshift4/ose-console

Matching in nixpkgs

pkgs.odo

Developer-focused CLI for OpenShift and Kubernetes

  • nixos-unstable -

pkgs.todo

Simple todo cli program written in rust

  • nixos-unstable -

pkgs.ctodo

Simple ncurses-based task list manager

  • nixos-unstable -

pkgs.godot

Free and Open Source 2D and 3D game engine

pkgs.diodon

Aiming to be the best integrated clipboard manager for the Unity desktop

  • nixos-unstable -

pkgs.godot3

Free and Open Source 2D and 3D game engine (X11 tools)

  • nixos-unstable -

pkgs.komodo

Tool to build and deploy software on many servers

  • nixos-unstable -

pkgs.devtodo

Hierarchical command-line task manager

  • nixos-unstable -

pkgs.robodoc

Documentation Extraction Tool

pkgs.todoman

Standards-based task manager based on iCalendar

  • nixos-unstable -

pkgs.comodoro

CLI to manage your time

  • nixos-unstable -

pkgs.dadadodo

Markov chain-based text generator

  • nixos-unstable -

pkgs.mastodon

Self-hosted, globally interconnected microblogging software based on ActivityPub

  • nixos-unstable -

pkgs.todofi-sh

Todo-txt + Rofi = Todofi.sh

  • nixos-unstable -

pkgs.podofo_0_9

Library to work with the PDF file format

  • nixos-unstable -

pkgs.podofo_1_0

Library to work with the PDF file format

  • nixos-unstable -

pkgs.sleek-todo

Todo manager based on todo.txt syntax

  • nixos-unstable -

pkgs.godot3-mono

Free and Open Source 2D and 3D game engine (mono build)

  • nixos-unstable -

pkgs.podofo_0_10

Library to work with the PDF file format

  • nixos-unstable -

pkgs.godotpcktool

Standalone tool for extracting and creating Godot .pck files

  • nixos-unstable -

pkgs.libre-bodoni

Bodoni fonts adapted for today's web requirements

  • nixos-unstable -

pkgs.pomodoro-gtk

Simple and intuitive timer application (also named Planytimer)

  • nixos-unstable -

pkgs.autodock-vina

One of the fastest and most widely used open-source docking engines

  • nixos-unstable -

pkgs.godot3-server

Free and Open Source 2D and 3D game engine (server)

  • nixos-unstable -

pkgs.koodousfinder

Tool to allows users to search for and analyze Android apps

  • nixos-unstable -

pkgs.gnome-pomodoro

Time management utility for GNOME based on the pomodoro technique

  • nixos-unstable -

pkgs.godot3-headless

Free and Open Source 2D and 3D game engine (headless)

  • nixos-unstable -

pkgs.openpomodoro-cli

Command-line Pomodoro tracker which uses the Open Pomodoro Format

  • nixos-unstable -

pkgs.godot3-mono-server

Free and Open Source 2D and 3D game engine (mono server)

  • nixos-unstable -

pkgs.godot3-debug-server

Free and Open Source 2D and 3D game engine (debug server)

  • nixos-unstable -

pkgs.gnomeExtensions.todo

Lightweight and user-friendly extension designed to help you manage your tasks efficiently. With a minimalistic interface, it allows you to add, modify, and delete tasks effortlessly. No complicated settings, just pure productivity!

  • nixos-unstable -
    • nixpkgs-unstable 5

Package maintainers