Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2024-32983
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Misskey allows the impersonation and takeover of remote accounts with unnormalized signed activities
Source: NVD (National Vulnerability Database)
Vulnerability Description
Misskey is an open source, decentralized microblogging platform. Misskey doesn't perform proper normalization on the JSON structures of incoming signed ActivityPub activity objects before processing them, allowing threat actors to spoof the contents of signed activities and impersonate the authors of the original activities. This vulnerability is fixed in 2024.5.0.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
授权机制不正确
Source: NVD (National Vulnerability Database)
Vulnerability Title
Misskey 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Misskey是一套微型博客平台。 Misskey 2024.5.0 版本之前存在安全漏洞,该漏洞源于在处理传入的签名 ActivityPub 活动对象之前未对其 JSON 结构进行适当的规范化,这允许攻击者伪造签名活动的内容并冒充原始活动的作者。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
misskey-devmisskey < 2024.5.0 -
II. Public POCs for CVE-2024-32983
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2024-32983
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2024-32983

No comments yet


Leave a comment