CVE-2022-24307: Critical severity mastodon vulnerability
Published Feb 3, 2022
·Updated
Mastodon before 3.3.2 and 3.4.x before 3.4.6 has incorrect access control because it does not compact incoming signed JSON-LD activities. (JSON-LD signing has been supported since version 1.6.0.)
Affected Software
2 affected components
Joinmastodon Mastodon<3.3.2
Joinmastodon Mastodon>=3.4.0<3.4.6
Event History
Feb 3, 2022
CVE Published
via MITRE·07:06 PM
Data Sourced
via MITRE·07:06 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this Mastodon vulnerability?
The vulnerability ID is CVE-2022-24307.
2
What is the severity of vulnerability CVE-2022-24307?
The severity of vulnerability CVE-2022-24307 is critical with a CVSS score of 9.8.
3
What is the affected software for vulnerability CVE-2022-24307?
The affected software for vulnerability CVE-2022-24307 is Mastodon version up to 3.3.2 and version 3.4.0 to 3.4.6.
4
How does vulnerability CVE-2022-24307 impact the system?
Vulnerability CVE-2022-24307 allows incorrect access control due to the failure to compact incoming signed JSON-LD activities.
5
How can I fix vulnerability CVE-2022-24307 in Mastodon?
To fix vulnerability CVE-2022-24307, update your Mastodon installation to version 3.3.2 or higher for versions up to 3.3.2, and update to version 3.4.6 for versions 3.4.0 to 3.4.6.