Mastodon vulnerability – admins must update with urgency

A vulnerability in Mastodon’s origin validation has been discovered. Admins are urged to update to fix this flaw as soon as possible.

With a 9.4 severity score, exploiting CVE-2024-23832 potentially allows attackers to take over Mastodon accounts remotely.

Critical vulnerability in Mastodon is pounced upon by fast-acting admins, The Register

Every Mastodon version prior to 3.5.17 is vulnerable, as are 4.0.x versions before 4.0.13, 4.1.x versions before 4.1.13, and 4.2.x versions before 4.2.5.

“Due to insufficient origin validation in all Mastodon, attackers can impersonate and take over any remote account,” the maintainers said in a terse advisory.

Mastodon Vulnerability Allows Hackers to Hijack Any Decentralized Account, The Hacker News

Devs are keeping the exact details private so that admins have a few weeks to upgrade and patch the problem.

What to know about Threads

Back on Jul 5, 2023, Eugen Rochko wrote about Threads and its intention to use ActivtyPub (thus federating with Mastodon).

What is noteworthy about this launch is that Threads intends to become part of the decentralized social web by using the same standard protocol as Mastodon, ActivityPub. There’s been a lot of speculation around what Threads will be and what it means for Mastodon. We’ve put together some of the most common questions and our responses based on what was launched today.

What to know about Threads, Eugen Rochko, blog.joinmastodon.org