CVE-2022-46405: High severity mastodon vulnerability
Mastodon through 4.0.2 allows attackers to cause a denial of service (large Sidekiq pull queue) by creating bot accounts that follow attacker-controlled accounts on certain other servers associated with a wildcard DNS A record, such that there is uncontrolled recursion of attacker-generated messages.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Mastodon vulnerability?
The vulnerability ID for this Mastodon vulnerability is CVE-2022-46405.
What is the severity of CVE-2022-46405?
The severity of CVE-2022-46405 is high, with a severity value of 7.5.
What are the affected software versions of CVE-2022-46405?
The affected software version of CVE-2022-46405 is Mastodon through version 4.0.2.
How does CVE-2022-46405 allow a denial of service attack?
CVE-2022-46405 allows a denial of service attack by creating bot accounts that follow attacker-controlled accounts on certain other servers associated with a wildcard DNS A record, causing uncontrolled recursion of attacker-generated messages.
Are there any references or resources for CVE-2022-46405?
Yes, you can find more information about CVE-2022-46405 at the following links: - [https://borg.social/notes/98bcoo2t1n](https://borg.social/notes/98bcoo2t1n) - [https://hackmd.io/rD9nsTz1QeuPT-erxqjY-A](https://hackmd.io/rD9nsTz1QeuPT-erxqjY-A)