CVE-2022-24307

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/02/2022
Last modified:
09/02/2022

Description

Mastodon before 3.3.2 and 3.4.x before 3.4.6 has incorrect access control because it does not compact incoming signed JSON-LD activities. (JSON-LD signing has been supported since version 1.6.0.)

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:joinmastodon:mastodon:*:*:*:*:*:*:*:* 3.3.2 (excluding)
cpe:2.3:a:joinmastodon:mastodon:*:*:*:*:*:*:*:* 3.4.0 (including) 3.4.6 (excluding)