CVE-2023-43793
Misskey is an open source, decentralized social media platform. Prior to version 2023.9.0, by editing the URL, a user ca
Misskey is an open source, decentralized social media platform. Prior to version 2023.9.0, by editing the URL, a user can bypass the authentication of the Bull dashboard, which is the job queue management UI, and access it. Version 2023.9.0 contains a fix.
There are no known workarounds.
HIGH · CVSS 7.5
EPSS 0.00214
Schedule remediation
- SSVC automatable: yes - attacks can be scripted at scale
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0