CVE-2023-36460
Starting in version 3.5.0 and prior to versions 3.5.9, 4.0.5, and 4.1.3, attackers using carefully crafted media files can cause Mastodon's media processing code to create arbitrary files at any location.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 40.1%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 3.5.0 and prior to versions 3.5.9, 4.0.5, and 4.1.3, attackers using carefully crafted media files can cause Mastodon's media processing code to create arbitrary files at any location. This allows attackers to create and overwrite any file Mastodon has access to, allowing Denial of Service and arbitrary Remote Code Execution. Versions 3.5.9, 4.0.5, and 4.1.3 contain a patch for this issue.
- CVSS 3.1
- 9.9 CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 40.11% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- joinmastodon/mastodon
- Source
- security-advisories@github.com
References
- http://www.openwall.com/lists/oss-security/2023/07/06/4Mailing List
- https://github.com/mastodon/mastodon/commit/dc8f1fbd976ae544720a4e07120d9a91b2722440Patch, Third Party Advisory
- https://github.com/mastodon/mastodon/releases/tag/v3.5.9Third Party Advisory
- https://github.com/mastodon/mastodon/releases/tag/v4.0.5Third Party Advisory
- https://github.com/mastodon/mastodon/releases/tag/v4.1.3Third Party Advisory
- https://github.com/mastodon/mastodon/security/advisories/GHSA-9928-3cp5-93fmThird Party Advisory
- http://www.openwall.com/lists/oss-security/2023/07/06/4Mailing List
- https://github.com/mastodon/mastodon/commit/dc8f1fbd976ae544720a4e07120d9a91b2722440Patch, Third Party Advisory
- https://github.com/mastodon/mastodon/releases/tag/v3.5.9Third Party Advisory
- https://github.com/mastodon/mastodon/releases/tag/v4.0.5Third Party Advisory
- https://github.com/mastodon/mastodon/releases/tag/v4.1.3Third Party Advisory
- https://github.com/mastodon/mastodon/security/advisories/GHSA-9928-3cp5-93fmThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.