CVE-2022-46405

Mastodon through 4.0.2 allows attackers to cause a denial of service (large Sidekiq pull queue) by creating bot accounts that follow attacker-controlled accounts on certain other servers associated with a wildcard DNS A record, such that there is uncontrolled recursion of attacker-generated messages.
References
Link Resource
https://borg.social/notes/98bcoo2t1n Issue Tracking Third Party Advisory
https://hackmd.io/rD9nsTz1QeuPT-erxqjY-A Exploit Issue Tracking Third Party Advisory
https://borg.social/notes/98bcoo2t1n Issue Tracking Third Party Advisory
https://hackmd.io/rD9nsTz1QeuPT-erxqjY-A Exploit Issue Tracking Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:joinmastodon:mastodon:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:30

Type Values Removed Values Added
Summary
  • (es) Mastodon hasta 4.0.2 permite a los atacantes provocar una Denegación de Servicio (DoS) (gran cola de extracción de Sidekiq) mediante la creación de cuentas de bot que siguen cuentas controladas por el atacante en ciertos otros servidores asociados con un registro DNS A comodín, de modo que existe una recursión incontrolada de mensajes generados por el atacante.
References () https://borg.social/notes/98bcoo2t1n - Issue Tracking, Third Party Advisory () https://borg.social/notes/98bcoo2t1n - Issue Tracking, Third Party Advisory
References () https://hackmd.io/rD9nsTz1QeuPT-erxqjY-A - Exploit, Issue Tracking, Third Party Advisory () https://hackmd.io/rD9nsTz1QeuPT-erxqjY-A - Exploit, Issue Tracking, Third Party Advisory

Information

Published : 2022-12-04 04:15

Updated : 2025-04-24 16:15


NVD link : CVE-2022-46405

Mitre link : CVE-2022-46405

CVE.ORG link : CVE-2022-46405


JSON object : View

Products Affected

joinmastodon

  • mastodon
CWE
CWE-674

Uncontrolled Recursion