CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
EPSS
Percentile
68.3%
Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authentication. Starting in version 2.5.0 and prior to versions 3.5.8, 4.0.4, and 4.1.2, the LDAP query made during login is insecure and the attacker can perform LDAP injection attack to leak arbitrary attributes from LDAP database. This issue is fixed in versions 3.5.8, 4.0.4, and 4.1.2.
[
{
"vendor": "mastodon",
"product": "mastodon",
"versions": [
{
"version": ">= 2.5.0, < 3.5.8",
"status": "affected"
},
{
"version": ">= 4.0.0, < 4.0.4",
"status": "affected"
},
{
"version": ">= 4.1.0, < 4.1.2",
"status": "affected"
}
]
}
]
www.openwall.com/lists/oss-security/2023/07/06/6
github.com/mastodon/mastodon/blob/94cbd808b5b3e7999c7e77dc724b7e8c9dd2bdec/app/models/concerns/ldap_authenticable.rb#L7-L14
github.com/mastodon/mastodon/blob/94cbd808b5b3e7999c7e77dc724b7e8c9dd2bdec/config/initializers/devise.rb#L398-L414
github.com/mastodon/mastodon/pull/24379
github.com/mastodon/mastodon/releases/tag/v3.5.8
github.com/mastodon/mastodon/releases/tag/v4.0.4
github.com/mastodon/mastodon/releases/tag/v4.1.2
github.com/mastodon/mastodon/security/advisories/GHSA-38g9-pfm9-gfqv