CVE-2022-24307
Mastodon before 3.3.2 and 3.4.x before 3.4.6 has incorrect access control because it does not compact incoming signed JS
Mastodon before 3.3.2 and 3.4.x before 3.4.6 has incorrect access control because it does not compact incoming signed JSON-LD activities. (JSON-LD signing has been supported since version 1.6.0.)
CRITICAL · CVSS 9.8
EPSS 0.00367
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0