CVE-2023-36460 is a critical arbitrary file creation vulnerability affecting Mastodon versions 3.5.0 through 3.5.8, 4.0.0 through 4.0.4, and 4.1.0 through 4.1.2. Attackers can exploit this by uploading specially crafted media files, leading to arbitrary file creation or overwriting on the server. This allows for Denial of Service and Remote Code Execution, with a CVSS score of 9.9 (Critical) due to its network attack vector and low attack complexity. While there is no public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, indicating high awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.5.0, < 3.5.9CPE matchmatch criteria | cpe:2.3:a:joinmastodon:mastodon:*:*:*:*:*:*:*:* | ||
>= 4.0.0, < 4.0.5CPE matchmatch criteria | cpe:2.3:a:joinmastodon:mastodon:*:*:*:*:*:*:*:* | ||
>= 4.1.0, < 4.1.3CPE matchmatch criteria | cpe:2.3:a:joinmastodon:mastodon:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.