logo

Mastodon vulnerability allows attackers to take over accounts

ID: 11d837ee-60bc-542b-8881-99df932b290a

STIX ID: report--11d837ee-60bc-542b-8881-99df932b290a

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2024-02-03

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Mastodon patched a critical vulnerability (CVE-2024-23832, CVSS 9.4) that allowed attackers to impersonate and take over remote user accounts due to insufficient origin validation; all instances running versions prior to 3.5.17, 4.0.13, 4.1.13, and 4.2.5 are affected and administrators are urged to upgrade to 4.2.5 immediately, while Mastodon withheld technical details until a scheduled disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.