logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2023-28853

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2023-28853

Description:
Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authentication. Starting in version 2.5.0 and prior to versions 3.5.8, 4.0.4, and 4.1.2, the LDAP query made during login is insecure and the attacker can perform LDAP injection attack to leak arbitrary attributes from LDAP database. This issue is fixed in versions 3.5.8, 4.0.4, and 4.1.2.
Last updated date:
07/07/2023
Type:
exploit
Confidence:
HIGH
Date of publishing:
04/10/2023
Reference url to background

https://github.com/mastodon/mastodon/security/advisories/GHSA-38g9-pfm9-gfqv

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy