CVE-2023-28853
Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authentication.
Does this matter?
Lower severity and a low EPSS score (1.28%). Track it; it rarely justifies an emergency change on its own.
Description
Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authentication. Starting in version 2.5.0 and prior to versions 3.5.8, 4.0.4, and 4.1.2, the LDAP query made during login is insecure and the attacker can perform LDAP injection attack to leak arbitrary attributes from LDAP database. This issue is fixed in versions 3.5.8, 4.0.4, and 4.1.2.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.28% probability · 68th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-90, CWE-74
- Affected
- joinmastodon/mastodon
- Source
- security-advisories@github.com
References
- http://www.openwall.com/lists/oss-security/2023/07/06/6
- https://github.com/mastodon/mastodon/blob/94cbd808b5b3e7999c7e77dc724b7e8c9dd2bdec/app/models/concerns/ldap_authenticable.rb#L7-L14Product
- https://github.com/mastodon/mastodon/blob/94cbd808b5b3e7999c7e77dc724b7e8c9dd2bdec/config/initializers/devise.rb#L398-L414Product
- https://github.com/mastodon/mastodon/pull/24379Patch
- https://github.com/mastodon/mastodon/releases/tag/v3.5.8Release Notes
- https://github.com/mastodon/mastodon/releases/tag/v4.0.4Release Notes
- https://github.com/mastodon/mastodon/releases/tag/v4.1.2Release Notes
- https://github.com/mastodon/mastodon/security/advisories/GHSA-38g9-pfm9-gfqvExploit, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2023/07/06/6
- https://github.com/mastodon/mastodon/blob/94cbd808b5b3e7999c7e77dc724b7e8c9dd2bdec/app/models/concerns/ldap_authenticable.rb#L7-L14Product
- https://github.com/mastodon/mastodon/blob/94cbd808b5b3e7999c7e77dc724b7e8c9dd2bdec/config/initializers/devise.rb#L398-L414Product
- https://github.com/mastodon/mastodon/pull/24379Patch
- https://github.com/mastodon/mastodon/releases/tag/v3.5.8Release Notes
- https://github.com/mastodon/mastodon/releases/tag/v4.0.4Release Notes
- https://github.com/mastodon/mastodon/releases/tag/v4.1.2Release Notes
- https://github.com/mastodon/mastodon/security/advisories/GHSA-38g9-pfm9-gfqvExploit, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.