CVE-2024-32983 is a high-severity vulnerability affecting Misskey, an open-source decentralized microblogging platform. The flaw stems from improper normalization of JSON structures in incoming signed ActivityPub activity objects, enabling attackers to spoof content and impersonate original authors. With a CVSS score of 7.5, this vulnerability can be exploited remotely with low complexity, leading to high integrity impacts without requiring user interaction. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the issue is addressed in Misskey version 2024.5.0.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2024.5.0CPE matchmatch criteria | cpe:2.3:a:misskey:misskey:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.