Vulnerabilities
Vulnerable Software
Joinmastodon:  >> Mastodon  >> 0.7  Security Vulnerabilities
app/models/user.rb in Mastodon before 3.5.0 allows a bypass of e-mail restrictions.
CVSS Score
5.3
EPSS Score
0.002
Published
2022-05-24
Mastodon before 3.3.2 and 3.4.x before 3.4.6 has incorrect access control because it does not compact incoming signed JSON-LD activities. (JSON-LD signing has been supported since version 1.6.0.)
CVSS Score
9.8
EPSS Score
0.003
Published
2022-02-03
Prototype Pollution in GitHub repository mastodon/mastodon prior to 3.5.0.
CVSS Score
7.4
EPSS Score
0.303
Published
2022-02-02
Mastodon before 2.6.3 mishandles timeouts of incompletely established sessions.
CVSS Score
9.8
EPSS Score
0.016
Published
2019-09-22


Contact Us

Shodan ® - All rights reserved