Записи joinmastodon
42 опубликованных записей вендора joinmastodon.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-770 Allocation of Resources Without Limits or Throttling5
- CWE-863 Incorrect Authorization4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-613 Insufficient Session Expiration3
- CWE-862 Missing Authorization2
- CWE-918 Server-Side Request Forgery (SSRF)2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
42 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
51В плане | CVE-2023-36460Эксплойта нет | Mastodon vulnerable to arbitrary file creation through media attachmentsjoinmastodon · mastodon · CWE-22 | Критическая9,9 | — | 40,1 % | 6 июл. 2023 г. |
40В плане | CVE-2018-21018Эксплойта нет | Mastodon before 2.6.3 mishandles timeouts of incompletely established sessions.joinmastodon · mastodon · CWE-613 | Критическая9,8 | — | 2,6 % | 22 сент. 2019 г. |
40В плане | CVE-2024-23832Эксплойта нет | Mastodon Remote user impersonation and takeoverjoinmastodon · mastodon · CWE-290 | Критическая9,8 | — | 2,5 % | 1 февр. 2024 г. |
39Наблюдать | CVE-2022-24307Эксплойта нет | Mastodon before 3.3.2 and 3.4.x before 3.4.6 has incorrect access control because it does not compact incoming signed JSON-LD activities.joinmastodon · mastodon · CWE-863 | Критическая9,8 | — | 1,4 % | 3 февр. 2022 г. |
39Наблюдать | CVE-2022-2166Эксплойта нет | Improper Restriction of Excessive Authentication Attempts in mastodon/mastodonjoinmastodon · mastodon · CWE-307 | Критическая9,8 | — | 1,1 % | 15 нояб. 2022 г. |
32Наблюдать | CVE-2024-37903Эксплойта нет | Mastodon has improper authorship check on audience extension for existing postsjoinmastodon · mastodon · CWE-862 | Высокая8,2 | — | 0,5 % | 5 июл. 2024 г. |
32Наблюдать | CVE-2026-41259Эксплойта нет | Mastodon: Insufficient verification of email addressesjoinmastodon · mastodon · CWE-841 | Высокая8,2 | — | 0,4 % | 23 апр. 2026 г. |
30Наблюдать | CVE-2023-36461Эксплойта нет | Mastodon vulnerable to Denial of Service through slow HTTP responsesjoinmastodon · mastodon · CWE-770 | Высокая7,5 | — | 1,3 % | 6 июл. 2023 г. |
30Наблюдать | CVE-2022-46405Эксплойта нет | Mastodon through 4.0.2 allows attackers to cause a denial of service (large Sidekiq pull queue) by creating bot accounts that follow attackejoinmastodon · mastodon · CWE-674 | Высокая7,5 | — | 0,9 % | 4 дек. 2022 г. |
30Наблюдать | CVE-2023-42451Эксплойта нет | Mastodon Invalid Domain Name Normalization vulnerabilityjoinmastodon · mastodon · CWE-706 | Высокая7,5 | — | 0,7 % | 19 сент. 2023 г. |
30Наблюдать | CVE-2026-23962Эксплойта нет | Mastodon vulnerable to Denial of Service from a single post (client/server)joinmastodon · mastodon · CWE-770 | Высокая7,5 | — | 0,6 % | 21 янв. 2026 г. |
30Наблюдать | CVE-2025-54879Эксплойта нет | Mastodon e‑mail throttle misconfiguration allows unlimited email confirmations against unconfirmed emailsjoinmastodon · mastodon · CWE-770 | Высокая7,5 | — | 0,5 % | 5 авг. 2025 г. |
30Наблюдать | CVE-2024-25623Эксплойта нет | Lack of media type verification of Activity Streams objects allows impersonation of remote accountsjoinmastodon · mastodon · CWE-434 | Высокая7,7 | — | 0,5 % | 19 февр. 2024 г. |
30Наблюдать | CVE-2023-49952Эксплойта нет | Mastodon 4.1.x before 4.1.17 and 4.2.x before 4.2.9 allows a bypass of rate limiting via a crafted HTTP request header.joinmastodon · mastodon · CWE-79 | Высокая7,5 | — | 0,5 % | 18 нояб. 2024 г. |
30Наблюдать | CVE-2023-42450Эксплойта нет | Mastodon Server-Side Request Forgery vulnerabilityjoinmastodon · mastodon · CWE-113 | Высокая7,5 | — | 0,5 % | 19 сент. 2023 г. |
29Наблюдать | CVE-2024-25618Эксплойта нет | External OpenID Connect Account Takeover by E-Mail Change in mastodonjoinmastodon · mastodon · CWE-287 | Высокая7,4 | — | 0,5 % | 14 февр. 2024 г. |
28Наблюдать | CVE-2026-22245Эксплойта нет | Mastodon has SSRF Protection bypassjoinmastodon · mastodon · CWE-918 | Высокая7,1 | — | 0,3 % | 8 янв. 2026 г. |
26Наблюдать | CVE-2023-28853Эксплойта нет | Mastodon's blind LDAP injection in login allows the attacker to leak arbitrary attributes from LDAP databasejoinmastodon · mastodon · CWE-90 | Средняя6,5 | — | 1,3 % | 4 апр. 2023 г. |
26Наблюдать | CVE-2026-25540Эксплойта нет | Mastodon's signature-dependent ActivityPub collection responses cached under signature-independent keys (Web Cache Poisoning via `Rails.cache`)joinmastodon · mastodon · CWE-524 | Средняя6,5 | — | 0,4 % | 4 февр. 2026 г. |
26Наблюдать | CVE-2026-23963Эксплойта нет | Mastodon missing length limits on list names, filter names, and filter keywordsjoinmastodon · mastodon · CWE-770 | Средняя6,5 | — | 0,3 % | 21 янв. 2026 г. |
25Наблюдать | CVE-2022-0432Proof of concept | Prototype Pollution in mastodon/mastodonjoinmastodon · mastodon · CWE-1321 | Средняя6,1 | — | 4,4 % | 2 февр. 2022 г. |
24Наблюдать | CVE-2023-36459Эксплойта нет | Mastodon vulnerable to Cross-site Scripting through oEmbed preview cardsjoinmastodon · mastodon · CWE-79 | Средняя6,1 | — | 1,2 % | 6 июл. 2023 г. |
24Наблюдать | CVE-2026-33868Proof of concept | Mastodon has a GET-Based Open Redirect via '/web/%2F<domain>'joinmastodon · mastodon · CWE-601 | Средняя6,1 | — | 0,6 % | 27 мар. 2026 г. |
23Наблюдать | CVE-2024-34535Эксплойта нет | In Mastodon 4.1.6, API endpoint rate limiting can be bypassed by setting a crafted HTTP request header.joinmastodon · mastodon · CWE-444 | Средняя5,9 | — | 0,4 % | 3 окт. 2024 г. |
21Наблюдать | CVE-2022-31263Эксплойта нет | app/models/user.rb in Mastodon before 3.5.0 allows a bypass of e-mail restrictions.joinmastodon · mastodon | Средняя5,3 | — | 0,9 % | 24 мая 2022 г. |
- CVE-2023-3646051В плане
Mastodon vulnerable to arbitrary file creation through media attachments
КритическаяCVSS 9,9Эксплойта нетEPSS 40 %joinmastodon · mastodon6 июл. 2023 г.
- CVE-2018-2101840В плане
Mastodon before 2.6.3 mishandles timeouts of incompletely established sessions.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %joinmastodon · mastodon22 сент. 2019 г.
- CVE-2024-2383240В плане
Mastodon Remote user impersonation and takeover
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %joinmastodon · mastodon1 февр. 2024 г.
- CVE-2022-2430739Наблюдать
Mastodon before 3.3.2 and 3.4.x before 3.4.6 has incorrect access control because it does not compact incoming signed JSON-LD activities.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %joinmastodon · mastodon3 февр. 2022 г.
- CVE-2022-216639Наблюдать
Improper Restriction of Excessive Authentication Attempts in mastodon/mastodon
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %joinmastodon · mastodon15 нояб. 2022 г.
- CVE-2024-3790332Наблюдать
Mastodon has improper authorship check on audience extension for existing posts
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %joinmastodon · mastodon5 июл. 2024 г.
- CVE-2026-4125932Наблюдать
Mastodon: Insufficient verification of email addresses
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %joinmastodon · mastodon23 апр. 2026 г.
- CVE-2023-3646130Наблюдать
Mastodon vulnerable to Denial of Service through slow HTTP responses
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %joinmastodon · mastodon6 июл. 2023 г.
- CVE-2022-4640530Наблюдать
Mastodon through 4.0.2 allows attackers to cause a denial of service (large Sidekiq pull queue) by creating bot accounts that follow attacke
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %joinmastodon · mastodon4 дек. 2022 г.
- CVE-2023-4245130Наблюдать
Mastodon Invalid Domain Name Normalization vulnerability
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %joinmastodon · mastodon19 сент. 2023 г.
- CVE-2026-2396230Наблюдать
Mastodon vulnerable to Denial of Service from a single post (client/server)
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %joinmastodon · mastodon21 янв. 2026 г.
- CVE-2025-5487930Наблюдать
Mastodon e‑mail throttle misconfiguration allows unlimited email confirmations against unconfirmed emails
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %joinmastodon · mastodon5 авг. 2025 г.
- CVE-2024-2562330Наблюдать
Lack of media type verification of Activity Streams objects allows impersonation of remote accounts
ВысокаяCVSS 7,7Эксплойта нетEPSS 1 %joinmastodon · mastodon19 февр. 2024 г.
- CVE-2023-4995230Наблюдать
Mastodon 4.1.x before 4.1.17 and 4.2.x before 4.2.9 allows a bypass of rate limiting via a crafted HTTP request header.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %joinmastodon · mastodon18 нояб. 2024 г.
- CVE-2023-4245030Наблюдать
Mastodon Server-Side Request Forgery vulnerability
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %joinmastodon · mastodon19 сент. 2023 г.
- CVE-2024-2561829Наблюдать
External OpenID Connect Account Takeover by E-Mail Change in mastodon
ВысокаяCVSS 7,4Эксплойта нетEPSS 0 %joinmastodon · mastodon14 февр. 2024 г.
- CVE-2026-2224528Наблюдать
Mastodon has SSRF Protection bypass
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %joinmastodon · mastodon8 янв. 2026 г.
- CVE-2023-2885326Наблюдать
Mastodon's blind LDAP injection in login allows the attacker to leak arbitrary attributes from LDAP database
СредняяCVSS 6,5Эксплойта нетEPSS 1 %joinmastodon · mastodon4 апр. 2023 г.
- CVE-2026-2554026Наблюдать
Mastodon's signature-dependent ActivityPub collection responses cached under signature-independent keys (Web Cache Poisoning via `Rails.cache`)
СредняяCVSS 6,5Эксплойта нетEPSS 0 %joinmastodon · mastodon4 февр. 2026 г.
- CVE-2026-2396326Наблюдать
Mastodon missing length limits on list names, filter names, and filter keywords
СредняяCVSS 6,5Эксплойта нетEPSS 0 %joinmastodon · mastodon21 янв. 2026 г.
- CVE-2022-043225Наблюдать
Prototype Pollution in mastodon/mastodon
СредняяCVSS 6,1Proof of conceptEPSS 4 %joinmastodon · mastodon2 февр. 2022 г.
- CVE-2023-3645924Наблюдать
Mastodon vulnerable to Cross-site Scripting through oEmbed preview cards
СредняяCVSS 6,1Эксплойта нетEPSS 1 %joinmastodon · mastodon6 июл. 2023 г.
- CVE-2026-3386824Наблюдать
Mastodon has a GET-Based Open Redirect via '/web/%2F<domain>'
СредняяCVSS 6,1Proof of conceptEPSS 1 %joinmastodon · mastodon27 мар. 2026 г.
- CVE-2024-3453523Наблюдать
In Mastodon 4.1.6, API endpoint rate limiting can be bypassed by setting a crafted HTTP request header.
СредняяCVSS 5,9Эксплойта нетEPSS 0 %joinmastodon · mastodon3 окт. 2024 г.
- CVE-2022-3126321Наблюдать
app/models/user.rb in Mastodon before 3.5.0 allows a bypass of e-mail restrictions.
СредняяCVSS 5,3Эксплойта нетEPSS 1 %joinmastodon · mastodon24 мая 2022 г.