Temporary Advertisements:
Ad
Ad
Ad
Mastodon TootRoot
by NotAThrow6397 - Monday July 10, 2023 at 02:27 PM
#1
Mastodon had to patch their software due to a big CVE with a score of 9.9/10 which allows for arbitrary file execution

https://youtube.com/watch?v=3KCyhltnz7w
[Image: XjbTbGW.gif]
Clowns
Reply
#2
tl;dw: several major vulns were found in mastodon during an audit

Critical:

Tootroot/ Arbitrary file creation through media attachments : "Using carefully crafted media files, attackers can cause Mastodon's media processing code to create arbitrary files at any location. Impact : This allows attackers to create and overwrite any file Mastodon has access to, allowing Denial of Service and arbitrary Remote Code Execution." - (https://github.com/mastodon/mastodon/sec...-3cp5-93fm)

XSS through oEmbed preview cardsĀ  - "Using carefully crafted oEmbed data, an attacker can bypass the HTML sanitization performed by Mastodon and include arbitrary HTML in oEmbed preview cards. Impact: This introduces a vector for Cross-site-scripting (XSS) payloads that can be rendered in the user's browser when a preview card for a malicious link is clicked through." - (https://github.com/mastodon/mastodon/sec...-vgcc-73hp)

update your shit and if you dont own the shit push the person who owns the shit to update the shit.

v4.1.2 and prior are vulnerable
Reply
#3
(Jul 10, 2023, 02:52 PM)happenstance Wrote: tl;dw: several major vulns were found in mastodon during an audit

Critical:

Tootroot/ Arbitrary file creation through media attachments : "Using carefully crafted media files, attackers can cause Mastodon's media processing code to create arbitrary files at any location. Impact : This allows attackers to create and overwrite any file Mastodon has access to, allowing Denial of Service and arbitrary Remote Code Execution." - (https://github.com/mastodon/mastodon/sec...-3cp5-93fm)

XSS through oEmbed preview cardsĀ  - "Using carefully crafted oEmbed data, an attacker can bypass the HTML sanitization performed by Mastodon and include arbitrary HTML in oEmbed preview cards. Impact: This introduces a vector for Cross-site-scripting (XSS) payloads that can be rendered in the user's browser when a preview card for a malicious link is clicked through." - (https://github.com/mastodon/mastodon/sec...-vgcc-73hp)

update your shit and if you dont own the shit push the person who owns the shit to update the shit.

way better TL;DR thanks :pomhappy:
[Image: XjbTbGW.gif]
Clowns
Reply
#4
haha LOL lets all move from Twitter to Mastadon!!!!
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Corruptiion of PLN [Indonesia] - 2025 Investigation Viral LordZeroDay 34 5,309 8 hours ago
Last Post: supervisorpusat
  Breached forums and clones? fda5b 7 3,060 Sep 07, 2026, 04:55 PM
Last Post: ShinyHunters
  Claude Mythos biyukean 7 998 Sep 05, 2026, 03:33 PM
Last Post: fkcca
  BreachForums Leak Free Data KingJulien 187 19,763 Sep 02, 2026, 09:50 PM
Last Post: kh3rnz
  Breached.hn Closes with Apologies Dissent Doe 1 1,423 Sep 02, 2026, 02:31 PM
Last Post: suicided

Forum Jump:


 Users browsing this forum: 1 Guest(s)