CVE-2023-42451: Mastodon Invalid Domain Name Normalization vulnerability
Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 3.5.14, 4.0.10, 4.1.8, and 4.2.0-rc2, under certain circumstances, attackers can exploit a flaw in domain name normalization to spoof domains they do not own. Versions 3.5.14, 4.0.10, 4.1.8, and 4.2.0-rc2 contain a patch for this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is Mastodon?
Mastodon is a free open-source social network server based on ActivityPub.
What is the severity of CVE-2023-42451?
The severity of CVE-2023-42451 is high with a CVSS score of 7.4.
How can an attacker exploit CVE-2023-42451?
Under certain circumstances, attackers can exploit a flaw in domain name normalization to spoof domains they do not own.
Which versions of Mastodon are affected by CVE-2023-42451?
Versions 3.5.14, 4.0.0 to 4.0.10, 4.1.0 to 4.1.8, and 4.2.0-rc2 are affected by CVE-2023-42451.
How do I fix CVE-2023-42451?
To fix CVE-2023-42451, update your Mastodon server to versions 3.5.14, 4.0.10, 4.1.8, or 4.2.0-rc2.