Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
By Recent Activity
joinmastodon mastodon vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2022-2166
Improper Restriction of Excessive Authentication Attempts in GitHub repository mastodon/mastodon prior to 4.0.0....
Joinmastodon Mastodon 4.0.0
Joinmastodon Mastodon
1 Github repository available
NA
CVE-2022-46405
Mastodon through 4.0.2 allows attackers to cause a denial of service (large Sidekiq pull queue) by creating bot accounts that follow attacker-controlled accounts on certain other servers associated with a wildcard DNS A record, such that there is uncontrolled recursion of...
Joinmastodon Mastodon
2 Github repositories available
NA
CVE-2022-48364
The undo_mark_statuses_as_sensitive method in app/services/approve_appeal_service.rb in Mastodon 3.5.x before 3.5.3 does not use the server's representative account, resulting in moderator identity disclosure when a moderator approves the appeal of a user whose status...
Joinmastodon Mastodon
1 Github repository available
4.3
CVSSv2
CVE-2022-0432
Prototype Pollution in GitHub repository mastodon/mastodon prior to 3.5.0....
Joinmastodon Mastodon
5
CVSSv2
CVE-2022-31263
app/models/user.rb in Mastodon before 3.5.0 allows a bypass of e-mail restrictions....
Joinmastodon Mastodon
7.5
CVSSv2
CVE-2018-21018
Mastodon before 2.6.3 mishandles timeouts of incompletely established sessions....
Joinmastodon Mastodon
1 Github repository available
7.5
CVSSv2
CVE-2022-24307
Mastodon before 3.3.2 and 3.4.x before 3.4.6 has incorrect access control because it does not compact incoming signed JSON-LD activities. (JSON-LD signing has been supported since version 1.6.0.)...
Joinmastodon Mastodon
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-25675
CVE-2023-21072
physical
CVE-2023-28446
encryption
CVE-2023-21076
server-side request forgery
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started