漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Mastodon Remote user impersonation and takeover
Vulnerability Description
Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authentication. Due to insufficient origin validation in all Mastodon, attackers can impersonate and take over any remote account. Every Mastodon version prior to 3.5.17 is vulnerable, as well as 4.0.x versions prior to 4.0.13, 4.1.x version prior to 4.1.13, and 4.2.x versions prior to 4.2.5.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
Vulnerability Type
使用欺骗进行的认证绕过
Vulnerability Title
Mastodon 安全漏洞
Vulnerability Description
Mastodon是一款基于ActivityPub的开源社交网络服务器。 Mastodon 3.5.17 之前、4.0.13 之前、4.1.13 之前、4.2.5 之前版本存在安全漏洞,该漏洞源于 ActivityPub Mastodon 允许配置 LDAP 进行身份验证,但验证不足,攻击者利用该漏洞可以冒充并接管任何远程帐户。
CVSS Information
N/A
Vulnerability Type
N/A