Mastodon vulnerability – admins must update with urgency

A vulnerability in Mastodon’s origin validation has been discovered. Admins are urged to update to fix this flaw as soon as possible.

With a 9.4 severity score, exploiting CVE-2024-23832 potentially allows attackers to take over Mastodon accounts remotely.

Critical vulnerability in Mastodon is pounced upon by fast-acting admins, The Register

Every Mastodon version prior to 3.5.17 is vulnerable, as are 4.0.x versions before 4.0.13, 4.1.x versions before 4.1.13, and 4.2.x versions before 4.2.5.

“Due to insufficient origin validation in all Mastodon, attackers can impersonate and take over any remote account,” the maintainers said in a terse advisory.

Mastodon Vulnerability Allows Hackers to Hijack Any Decentralized Account, The Hacker News

Devs are keeping the exact details private so that admins have a few weeks to upgrade and patch the problem.

Leave a Reply

Your email address will not be published. Required fields are marked *

You may use these HTML tags and attributes:

<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <s> <strike> <strong>

To respond on your own website, enter the URL of your response which should contain a link to this post's permalink URL. Your response will then appear (possibly after moderation) on this page. Want to update or remove your response? Update or delete your post and re-enter your post's URL again. (Find out more about Webmentions.)