A serious security issue that allows hostile actors to assume the identity of and take control of any account has been discovered by the decentralized social network Mastodon.
In a succinct warning, the maintainers stated that “attackers can impersonate and take over any remote account due to insufficient origin validation in all Mastodon.”
The vulnerability with the tracking number CVE-2024-23832 has been assigned a severity rating of 9.4 out of a possible 10. It has been acknowledged that security researcher arcanicanis found and reported it.
According to the description, it’s a “origin validation error” (CWE-346), and once this happens, an attacker can usually “access any functionality that is inadvertently accessible read more Mastodon Vulnerability Allows Hackers to Hijack Any Decentralized Account.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
