Skip to content

Arbitrary file creation through media attachments

Critical
Gargron published GHSA-9928-3cp5-93fm Jul 6, 2023

Package

No package listed

Affected versions

>= 3.5.0

Patched versions

4.1.3, 4.0.5, 3.5.9

Description

(This advisory describes an issue found by Cure53 as part of an audit performed at Mozilla's request)

Using carefully crafted media files, attackers can cause Mastodon's media processing code to create arbitrary files at any location.

Impact

This allows attackers to create and overwrite any file Mastodon has access to, allowing Denial of Service and arbitrary Remote Code Execution.

Severity

Critical
10.0
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CVE ID

CVE-2023-36460

Weaknesses

No CWEs

Credits