• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
mastodon vulnerability allows hackers to hijack any decentralized account

Mastodon Vulnerability Allows Hackers to Hijack Any Decentralized Account

You are here: Home / General Cyber Security News / Mastodon Vulnerability Allows Hackers to Hijack Any Decentralized Account
February 3, 2024

The decentralized social network Mastodon has disclosed a critical security flaw that allows malicious actors to impersonate and get over any account.

“Because of to inadequate origin validation in all Mastodon, attackers can impersonate and get more than any distant account,” the maintainers reported in a terse advisory.

The vulnerability, tracked as CVE-2024-23832, has a severity score of 9.4 out of a highest of 10. Security researcher arcanicanis has been credited with finding and reporting it.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


It has been explained as an “origin validation mistake” (CWE-346), which can usually permit an attacker to “access any performance that is inadvertently obtainable to the resource.”

Just about every Mastodon version prior to 3.5.17 is vulnerable, as are 4..x variations prior to 4..13, 4.1.x variations ahead of 4.1.13, and 4.2.x versions in advance of 4.2.5.

Mastodon claimed it truly is withholding added technological specifics about the flaw right up until February 15, 2024, to give admins ample time to update the server situations and stop the likelihood of exploitation.

Cybersecurity

“Any amount of depth would make it quite straightforward to appear up with an exploit,” it explained.

The federated mother nature of the platform usually means that it runs on independent servers (aka cases), independently hosted and operated by respective administrators who generate their personal policies and rules that are enforced locally.

This also implies that not only each instance has a one of a kind code of conduct, conditions of services, privacy coverage, and written content moderation guidelines, but it also needs each administrator to implement security updates in a timely manner to safe the scenarios against possible pitfalls.

The disclosure comes virtually 7 months right after Mastodon resolved two other critical flaws (CVE-2023-36460 and 2023-36459) that could have been weaponized by adversaries to induce denial-of-services (DoS) or realize distant code execution.

Observed this article intriguing? Observe us on Twitter  and LinkedIn to read through much more unique information we put up.


Some areas of this post are sourced from:
thehackernews.com

Previous Post: «anydesk hacked: popular remote desktop software mandates password reset AnyDesk Hacked: Popular Remote Desktop Software Mandates Password Reset
Next Post: U.S. Sanctions 6 Iranian Officials for Critical Infrastructure Cyber Attacks u.s. sanctions 6 iranian officials for critical infrastructure cyber attacks»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.