NA

CVE-2022-46405

Published: 04/12/2022 Updated: 06/12/2022
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Mastodon up to and including 4.0.2 allows malicious users to cause a denial of service (large Sidekiq pull queue) by creating bot accounts that follow attacker-controlled accounts on certain other servers associated with a wildcard DNS A record, such that there is uncontrolled recursion of attacker-generated messages.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

joinmastodon mastodon