CVE-2019-5961: High severity mastodon vulnerability
Published Jul 5, 2019
·Updated
The Android App 'Tootdon for Mastodon' version 3.4.1 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Affected Software
1 affected component
Mastodon-tootdon Tootdon For Mastodon Android<=3.4.1
Event History
Jul 5, 2019
CVE Published
via MITRE·01:20 PM
Data Sourced
via MITRE·01:20 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-5961?
CVE-2019-5961 is categorized as a high severity vulnerability due to its potential for man-in-the-middle attacks.
2
How do I fix CVE-2019-5961?
To fix CVE-2019-5961, update the Tootdon for Mastodon app to version 3.4.2 or later.
3
What types of attacks can CVE-2019-5961 allow?
CVE-2019-5961 can allow man-in-the-middle attackers to spoof servers and intercept sensitive information.
4
Which versions of Tootdon for Mastodon are affected by CVE-2019-5961?
CVE-2019-5961 affects Tootdon for Mastodon versions 3.4.1 and earlier.
5
What is the impact of CVE-2019-5961?
The impact of CVE-2019-5961 includes the potential exposure of sensitive user information due to insufficient SSL certificate verification.