CVE-2024-23832: Mastodon Remote user impersonation and takeover
Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authentication. Due to insufficient origin validation in all Mastodon, attackers can impersonate and take over any remote account. Every Mastodon version prior to 3.5.17 is vulnerable, as well as 4.0.x versions prior to 4.0.13, 4.1.x version prior to 4.1.13, and 4.2.x versions prior to 4.2.5.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mastodonto a version that resolves this vulnerability.Fixed in 3.5.17 - Upgrade
Upgrade
Mastodonto a version that resolves this vulnerability.Fixed in 4.0.13 - Upgrade
Upgrade
Mastodonto a version that resolves this vulnerability.Fixed in 4.1.13 - Upgrade
Upgrade
Mastodonto a version that resolves this vulnerability.Fixed in 4.2.5
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23832?
CVE-2024-23832 is considered a high severity vulnerability due to its potential for account impersonation and takeover.
How do I fix CVE-2024-23832?
To fix CVE-2024-23832, users should update their Mastodon installation to version 3.5.17 or later.
What versions of Mastodon are affected by CVE-2024-23832?
All versions of Mastodon prior to 3.5.17, including those between 4.0.0 and 4.2.5, are affected by CVE-2024-23832.
Can CVE-2024-23832 be exploited remotely?
Yes, CVE-2024-23832 can be exploited remotely by attackers to impersonate and take over accounts.
What type of vulnerability is CVE-2024-23832 classified as?
CVE-2024-23832 is classified as an authentication vulnerability due to insufficient origin validation.