Mastodon vulnerability – admins must update with urgency

A vulnerability in Mastodon’s origin validation has been discovered. Admins are urged to update to fix this flaw as soon as possible.

With a 9.4 severity score, exploiting CVE-2024-23832 potentially allows attackers to take over Mastodon accounts remotely.

Critical vulnerability in Mastodon is pounced upon by fast-acting admins, The Register

Every Mastodon version prior to 3.5.17 is vulnerable, as are 4.0.x versions before 4.0.13, 4.1.x versions before 4.1.13, and 4.2.x versions before 4.2.5.

“Due to insufficient origin validation in all Mastodon, attackers can impersonate and take over any remote account,” the maintainers said in a terse advisory.

Mastodon Vulnerability Allows Hackers to Hijack Any Decentralized Account, The Hacker News

Devs are keeping the exact details private so that admins have a few weeks to upgrade and patch the problem.