CVE-2022-0432 describes a Prototype Pollution vulnerability affecting Mastodon versions prior to 3.5.0. This flaw allows an attacker to inject arbitrary properties into JavaScript object prototypes, potentially leading to denial of service, information disclosure, or cross-site scripting. Rated as Medium severity with a CVSS score of 6.1, the vulnerability requires user interaction (UI:R) and can be exploited over the network (AV:N). While the attack complexity is low (AC:L), the potential impact is limited to partial confidentiality and integrity loss (C:L/I:L/A:N). Currently, there is no evidence of active exploitation, nor is it listed on CISA's KEV catalog. While no Metasploit or ExploitDB modules exist, Nuclei templates are available, indicating some exploitability. Community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.5.0CPE matchmatch criteria | cpe:2.3:a:joinmastodon:mastodon:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.