CVE-2024-25108 is a critical authorization bypass vulnerability in Pixelfed versions 0.10.4 through 0.11.9, allowing authenticated attackers to gain unauthorized access to administrative and moderator functionalities due to insufficient authorization checks. With a CVSS score of 8.8 (High), this vulnerability has a network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While a proof of concept exists, there is no evidence of active exploitation in the wild, nor are there public Metasploit or Nuclei modules. The vulnerability has garnered some community discussion, and users are strongly advised to upgrade to version 0.11.11 to mitigate the risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.10.4, < 0.11.11CPE matchmatch criteria | cpe:2.3:a:pixelfed:pixelfed:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.