CVE-2024-34535: Medium severity mastodon vulnerability
Published Oct 3, 2024
·Updated
In Mastodon 4.1.6, API endpoint rate limiting can be bypassed by setting a crafted HTTP request header.
Affected Software
3 affected components
Mastodon Mastodon
Joinmastodon Mastodon<=4.1.16
Joinmastodon Mastodon>=4.2.0<=4.2.8
Event History
Oct 3, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-34535?
The severity of CVE-2024-34535 is classified as medium due to the potential for bypassing API endpoint rate limiting.
2
How do I fix CVE-2024-34535?
To fix CVE-2024-34535, upgrade Mastodon to the latest version where the vulnerability has been addressed.
3
What software is affected by CVE-2024-34535?
CVE-2024-34535 affects Mastodon version 4.1.6.
4
What type of attack is possible with CVE-2024-34535?
CVE-2024-34535 allows an attacker to bypass rate limiting on API endpoints through crafted HTTP request headers.
5
Is there a known exploit for CVE-2024-34535?
As of now, there is no public knowledge of specific exploits actively targeting CVE-2024-34535.