First published: Sun Dec 04 2022(Updated: )
Mastodon through 4.0.2 allows attackers to cause a denial of service (large Sidekiq pull queue) by creating bot accounts that follow attacker-controlled accounts on certain other servers associated with a wildcard DNS A record, such that there is uncontrolled recursion of attacker-generated messages.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mastodon | <=4.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Mastodon vulnerability is CVE-2022-46405.
The severity of CVE-2022-46405 is high, with a severity value of 7.5.
The affected software version of CVE-2022-46405 is Mastodon through version 4.0.2.
CVE-2022-46405 allows a denial of service attack by creating bot accounts that follow attacker-controlled accounts on certain other servers associated with a wildcard DNS A record, causing uncontrolled recursion of attacker-generated messages.
Yes, you can find more information about CVE-2022-46405 at the following links: - [https://borg.social/notes/98bcoo2t1n](https://borg.social/notes/98bcoo2t1n) - [https://hackmd.io/rD9nsTz1QeuPT-erxqjY-A](https://hackmd.io/rD9nsTz1QeuPT-erxqjY-A)