BIT-mastodon-2023-36462

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/mastodon/BIT-mastodon-2023-36462.json
JSON Data
https://api.test.osv.dev/v1/vulns/BIT-mastodon-2023-36462
Aliases
Published
2024-03-06T10:56:16.089Z
Modified
2024-03-06T11:25:28.861Z
Summary
[none]
Details

Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 2.6.0 and prior to versions 3.5.9, 4.0.5, and 4.1.3, an attacker can craft a verified profile link using specific formatting to conceal arbitrary parts of the link, enabling it to appear to link to a different URL altogether. The link is visually misleading, but clicking on it will reveal the actual link. This can still be used for phishing, though, similar to IDN homograph attacks. Versions 3.5.9, 4.0.5, and 4.1.3 contain a patch for this issue.

Database specific
{
    "cpes": [
        "cpe:2.3:a:joinmastodon:mastodon:*:*:*:*:*:*:*:*"
    ],
    "severity": "Medium"
}
References

Affected packages

Bitnami / mastodon

Package

Name
mastodon
Purl
pkg:bitnami/mastodon

Severity

  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
2.6.0
Fixed
3.5.9
Introduced
4.0.0
Fixed
4.0.5
Introduced
4.1.0
Fixed
4.1.3