joinmastodon kayıtları
joinmastodon üreticisine ait 42 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-770 Allocation of Resources Without Limits or Throttling5
- CWE-863 Incorrect Authorization4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-613 Insufficient Session Expiration3
- CWE-862 Missing Authorization2
- CWE-918 Server-Side Request Forgery (SSRF)2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
42 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
51Planlayın | CVE-2023-36460İstismar yok | Mastodon vulnerable to arbitrary file creation through media attachmentsjoinmastodon · mastodon · CWE-22 | Kritik9,9 | — | %40,1 | 6 Tem 2023 |
40Planlayın | CVE-2018-21018İstismar yok | Mastodon before 2.6.3 mishandles timeouts of incompletely established sessions.joinmastodon · mastodon · CWE-613 | Kritik9,8 | — | %2,6 | 22 Eyl 2019 |
40Planlayın | CVE-2024-23832İstismar yok | Mastodon Remote user impersonation and takeoverjoinmastodon · mastodon · CWE-290 | Kritik9,8 | — | %2,5 | 1 Şub 2024 |
39İzleyin | CVE-2022-24307İstismar yok | Mastodon before 3.3.2 and 3.4.x before 3.4.6 has incorrect access control because it does not compact incoming signed JSON-LD activities.joinmastodon · mastodon · CWE-863 | Kritik9,8 | — | %1,4 | 3 Şub 2022 |
39İzleyin | CVE-2022-2166İstismar yok | Improper Restriction of Excessive Authentication Attempts in mastodon/mastodonjoinmastodon · mastodon · CWE-307 | Kritik9,8 | — | %1,1 | 15 Kas 2022 |
32İzleyin | CVE-2024-37903İstismar yok | Mastodon has improper authorship check on audience extension for existing postsjoinmastodon · mastodon · CWE-862 | Yüksek8,2 | — | %0,5 | 5 Tem 2024 |
32İzleyin | CVE-2026-41259İstismar yok | Mastodon: Insufficient verification of email addressesjoinmastodon · mastodon · CWE-841 | Yüksek8,2 | — | %0,4 | 23 Nis 2026 |
30İzleyin | CVE-2023-36461İstismar yok | Mastodon vulnerable to Denial of Service through slow HTTP responsesjoinmastodon · mastodon · CWE-770 | Yüksek7,5 | — | %1,3 | 6 Tem 2023 |
30İzleyin | CVE-2022-46405İstismar yok | Mastodon through 4.0.2 allows attackers to cause a denial of service (large Sidekiq pull queue) by creating bot accounts that follow attackejoinmastodon · mastodon · CWE-674 | Yüksek7,5 | — | %0,9 | 4 Ara 2022 |
30İzleyin | CVE-2023-42451İstismar yok | Mastodon Invalid Domain Name Normalization vulnerabilityjoinmastodon · mastodon · CWE-706 | Yüksek7,5 | — | %0,7 | 19 Eyl 2023 |
30İzleyin | CVE-2026-23962İstismar yok | Mastodon vulnerable to Denial of Service from a single post (client/server)joinmastodon · mastodon · CWE-770 | Yüksek7,5 | — | %0,6 | 21 Oca 2026 |
30İzleyin | CVE-2025-54879İstismar yok | Mastodon e‑mail throttle misconfiguration allows unlimited email confirmations against unconfirmed emailsjoinmastodon · mastodon · CWE-770 | Yüksek7,5 | — | %0,5 | 5 Ağu 2025 |
30İzleyin | CVE-2024-25623İstismar yok | Lack of media type verification of Activity Streams objects allows impersonation of remote accountsjoinmastodon · mastodon · CWE-434 | Yüksek7,7 | — | %0,5 | 19 Şub 2024 |
30İzleyin | CVE-2023-49952İstismar yok | Mastodon 4.1.x before 4.1.17 and 4.2.x before 4.2.9 allows a bypass of rate limiting via a crafted HTTP request header.joinmastodon · mastodon · CWE-79 | Yüksek7,5 | — | %0,5 | 18 Kas 2024 |
30İzleyin | CVE-2023-42450İstismar yok | Mastodon Server-Side Request Forgery vulnerabilityjoinmastodon · mastodon · CWE-113 | Yüksek7,5 | — | %0,5 | 19 Eyl 2023 |
29İzleyin | CVE-2024-25618İstismar yok | External OpenID Connect Account Takeover by E-Mail Change in mastodonjoinmastodon · mastodon · CWE-287 | Yüksek7,4 | — | %0,5 | 14 Şub 2024 |
28İzleyin | CVE-2026-22245İstismar yok | Mastodon has SSRF Protection bypassjoinmastodon · mastodon · CWE-918 | Yüksek7,1 | — | %0,3 | 8 Oca 2026 |
26İzleyin | CVE-2023-28853İstismar yok | Mastodon's blind LDAP injection in login allows the attacker to leak arbitrary attributes from LDAP databasejoinmastodon · mastodon · CWE-90 | Orta6,5 | — | %1,3 | 4 Nis 2023 |
26İzleyin | CVE-2026-25540İstismar yok | Mastodon's signature-dependent ActivityPub collection responses cached under signature-independent keys (Web Cache Poisoning via `Rails.cache`)joinmastodon · mastodon · CWE-524 | Orta6,5 | — | %0,4 | 4 Şub 2026 |
26İzleyin | CVE-2026-23963İstismar yok | Mastodon missing length limits on list names, filter names, and filter keywordsjoinmastodon · mastodon · CWE-770 | Orta6,5 | — | %0,3 | 21 Oca 2026 |
25İzleyin | CVE-2022-0432Kavram kanıtı | Prototype Pollution in mastodon/mastodonjoinmastodon · mastodon · CWE-1321 | Orta6,1 | — | %4,4 | 2 Şub 2022 |
24İzleyin | CVE-2023-36459İstismar yok | Mastodon vulnerable to Cross-site Scripting through oEmbed preview cardsjoinmastodon · mastodon · CWE-79 | Orta6,1 | — | %1,2 | 6 Tem 2023 |
24İzleyin | CVE-2026-33868Kavram kanıtı | Mastodon has a GET-Based Open Redirect via '/web/%2F<domain>'joinmastodon · mastodon · CWE-601 | Orta6,1 | — | %0,6 | 27 Mar 2026 |
23İzleyin | CVE-2024-34535İstismar yok | In Mastodon 4.1.6, API endpoint rate limiting can be bypassed by setting a crafted HTTP request header.joinmastodon · mastodon · CWE-444 | Orta5,9 | — | %0,4 | 3 Eki 2024 |
21İzleyin | CVE-2022-31263İstismar yok | app/models/user.rb in Mastodon before 3.5.0 allows a bypass of e-mail restrictions.joinmastodon · mastodon | Orta5,3 | — | %0,9 | 24 May 2022 |
- CVE-2023-3646051Planlayın
Mastodon vulnerable to arbitrary file creation through media attachments
KritikCVSS 9,9İstismar yokEPSS %40joinmastodon · mastodon6 Tem 2023
- CVE-2018-2101840Planlayın
Mastodon before 2.6.3 mishandles timeouts of incompletely established sessions.
KritikCVSS 9,8İstismar yokEPSS %3joinmastodon · mastodon22 Eyl 2019
- CVE-2024-2383240Planlayın
Mastodon Remote user impersonation and takeover
KritikCVSS 9,8İstismar yokEPSS %2joinmastodon · mastodon1 Şub 2024
- CVE-2022-2430739İzleyin
Mastodon before 3.3.2 and 3.4.x before 3.4.6 has incorrect access control because it does not compact incoming signed JSON-LD activities.
KritikCVSS 9,8İstismar yokEPSS %1joinmastodon · mastodon3 Şub 2022
- CVE-2022-216639İzleyin
Improper Restriction of Excessive Authentication Attempts in mastodon/mastodon
KritikCVSS 9,8İstismar yokEPSS %1joinmastodon · mastodon15 Kas 2022
- CVE-2024-3790332İzleyin
Mastodon has improper authorship check on audience extension for existing posts
YüksekCVSS 8,2İstismar yokEPSS %1joinmastodon · mastodon5 Tem 2024
- CVE-2026-4125932İzleyin
Mastodon: Insufficient verification of email addresses
YüksekCVSS 8,2İstismar yokEPSS %0joinmastodon · mastodon23 Nis 2026
- CVE-2023-3646130İzleyin
Mastodon vulnerable to Denial of Service through slow HTTP responses
YüksekCVSS 7,5İstismar yokEPSS %1joinmastodon · mastodon6 Tem 2023
- CVE-2022-4640530İzleyin
Mastodon through 4.0.2 allows attackers to cause a denial of service (large Sidekiq pull queue) by creating bot accounts that follow attacke
YüksekCVSS 7,5İstismar yokEPSS %1joinmastodon · mastodon4 Ara 2022
- CVE-2023-4245130İzleyin
Mastodon Invalid Domain Name Normalization vulnerability
YüksekCVSS 7,5İstismar yokEPSS %1joinmastodon · mastodon19 Eyl 2023
- CVE-2026-2396230İzleyin
Mastodon vulnerable to Denial of Service from a single post (client/server)
YüksekCVSS 7,5İstismar yokEPSS %1joinmastodon · mastodon21 Oca 2026
- CVE-2025-5487930İzleyin
Mastodon e‑mail throttle misconfiguration allows unlimited email confirmations against unconfirmed emails
YüksekCVSS 7,5İstismar yokEPSS %1joinmastodon · mastodon5 Ağu 2025
- CVE-2024-2562330İzleyin
Lack of media type verification of Activity Streams objects allows impersonation of remote accounts
YüksekCVSS 7,7İstismar yokEPSS %1joinmastodon · mastodon19 Şub 2024
- CVE-2023-4995230İzleyin
Mastodon 4.1.x before 4.1.17 and 4.2.x before 4.2.9 allows a bypass of rate limiting via a crafted HTTP request header.
YüksekCVSS 7,5İstismar yokEPSS %0joinmastodon · mastodon18 Kas 2024
- CVE-2023-4245030İzleyin
Mastodon Server-Side Request Forgery vulnerability
YüksekCVSS 7,5İstismar yokEPSS %0joinmastodon · mastodon19 Eyl 2023
- CVE-2024-2561829İzleyin
External OpenID Connect Account Takeover by E-Mail Change in mastodon
YüksekCVSS 7,4İstismar yokEPSS %0joinmastodon · mastodon14 Şub 2024
- CVE-2026-2224528İzleyin
Mastodon has SSRF Protection bypass
YüksekCVSS 7,1İstismar yokEPSS %0joinmastodon · mastodon8 Oca 2026
- CVE-2023-2885326İzleyin
Mastodon's blind LDAP injection in login allows the attacker to leak arbitrary attributes from LDAP database
OrtaCVSS 6,5İstismar yokEPSS %1joinmastodon · mastodon4 Nis 2023
- CVE-2026-2554026İzleyin
Mastodon's signature-dependent ActivityPub collection responses cached under signature-independent keys (Web Cache Poisoning via `Rails.cache`)
OrtaCVSS 6,5İstismar yokEPSS %0joinmastodon · mastodon4 Şub 2026
- CVE-2026-2396326İzleyin
Mastodon missing length limits on list names, filter names, and filter keywords
OrtaCVSS 6,5İstismar yokEPSS %0joinmastodon · mastodon21 Oca 2026
- CVE-2022-043225İzleyin
Prototype Pollution in mastodon/mastodon
OrtaCVSS 6,1Kavram kanıtıEPSS %4joinmastodon · mastodon2 Şub 2022
- CVE-2023-3645924İzleyin
Mastodon vulnerable to Cross-site Scripting through oEmbed preview cards
OrtaCVSS 6,1İstismar yokEPSS %1joinmastodon · mastodon6 Tem 2023
- CVE-2026-3386824İzleyin
Mastodon has a GET-Based Open Redirect via '/web/%2F<domain>'
OrtaCVSS 6,1Kavram kanıtıEPSS %1joinmastodon · mastodon27 Mar 2026
- CVE-2024-3453523İzleyin
In Mastodon 4.1.6, API endpoint rate limiting can be bypassed by setting a crafted HTTP request header.
OrtaCVSS 5,9İstismar yokEPSS %0joinmastodon · mastodon3 Eki 2024
- CVE-2022-3126321İzleyin
app/models/user.rb in Mastodon before 3.5.0 allows a bypass of e-mail restrictions.
OrtaCVSS 5,3İstismar yokEPSS %1joinmastodon · mastodon24 May 2022