Mastodon Vulnerability Allows Hackers to Hijack Any Decentralized Account
A serious security issue that allows hostile actors to assume the identity of and take control of any account has been discovered by the decentralized social network Mastodon.
In a succinct warning, the maintainers stated that "attackers can impersonate and take over any remote account due to insufficient origin validation in all Mastodon."
The vulnerability with the tracking number CVE-2024-23832 has been assigned a severity rating of 9.4 out of a possible 10. It has been acknowledged that security researcher arcanicanis found and reported it.
According to the description, it's a "origin validation error" (CWE-346), and once this happens, an attacker can usually "access any functionality that is inadvertently accessible read more Mastodon Vulnerability Allows Hackers to Hijack A...

