漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Misskey allows the impersonation and takeover of remote accounts with unnormalized signed activities
Vulnerability Description
Misskey is an open source, decentralized microblogging platform. Misskey doesn't perform proper normalization on the JSON structures of incoming signed ActivityPub activity objects before processing them, allowing threat actors to spoof the contents of signed activities and impersonate the authors of the original activities. This vulnerability is fixed in 2024.5.0.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
Vulnerability Type
授权机制不正确
Vulnerability Title
Misskey 安全漏洞
Vulnerability Description
Misskey是一套微型博客平台。 Misskey 2024.5.0 版本之前存在安全漏洞,该漏洞源于在处理传入的签名 ActivityPub 活动对象之前未对其 JSON 结构进行适当的规范化,这允许攻击者伪造签名活动的内容并冒充原始活动的作者。
CVSS Information
N/A
Vulnerability Type
N/A