Mastodon before 3.3.2 and 3.4.x before 3.4.6 has incorrect access control because it does not compact incoming signed JSON-LD activities. (JSON-LD signing has been supported since version 1.6.0.)
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://github.com/mastodon/mastodon/releases/tag/v3.4.6 | third party advisory release notes |
https://github.com/mastodon/mastodon/releases/tag/v3.3.2 | third party advisory release notes |