First published: Thu Feb 03 2022(Updated: )
Mastodon before 3.3.2 and 3.4.x before 3.4.6 has incorrect access control because it does not compact incoming signed JSON-LD activities. (JSON-LD signing has been supported since version 1.6.0.)
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mastodon | <3.3.2 | |
Mastodon | >=3.4.0<3.4.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-24307.
The severity of vulnerability CVE-2022-24307 is critical with a CVSS score of 9.8.
The affected software for vulnerability CVE-2022-24307 is Mastodon version up to 3.3.2 and version 3.4.0 to 3.4.6.
Vulnerability CVE-2022-24307 allows incorrect access control due to the failure to compact incoming signed JSON-LD activities.
To fix vulnerability CVE-2022-24307, update your Mastodon installation to version 3.3.2 or higher for versions up to 3.3.2, and update to version 3.4.6 for versions 3.4.0 to 3.4.6.