First published: Mon Apr 03 2023(Updated: )
** DISPUTED ** The Twitter Recommendation Algorithm through ec83d01 allows attackers to cause a denial of service (reduction of reputation score) by arranging for multiple Twitter accounts to coordinate negative signals regarding a target account, such as unfollowing, muting, blocking, and reporting, as exploited in the wild in March and April 2023. NOTE: Vendor states that allowing users to unfollow, mute, block, and report tweets and accounts and the impact of these negative engagements on Twitter’s ranking algorithm is a conscious design decision, rather than a security vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Twitter Recommendation Algorithm | <=2023-03-31 | |
<=2023-03-31 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-29218 is disputed and primarily concerns denial of service affecting reputation scores on Twitter.
There is currently no official fix for CVE-2023-29218, as it is a disputed vulnerability.
CVE-2023-29218 allows attacks such as coordinated negative actions like unfollowing, muting, blocking, and reporting a target account.
CVE-2023-29218 affects the Twitter Recommendation Algorithm versions up to March 31, 2023.
Yes, CVE-2023-29218 can impact individual users by reducing their reputation scores through coordinated attacks.