Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-24810: XSS vulnerability using authentication callback

Misskey is an open source, decentralized social media platform. Due to insufficient validation of the redirect URL during miauth authentication in Misskey, arbitrary JavaScript can be executed when a user allows the link. All versions below 13.3.1 (including 12.x) are affected. This has been fixed in version 13.3.1. Users are advised to upgrade. Users unable to upgrade should not allow authentication of untrusted apps.

CVE
#xss#vulnerability#java#auth

Impact

Misskeyのmiauth認証時において、リダイレクト先URLの検証が不十分なため、ユーザーが連携を許可した際に任意のJavaScriptを実行できます。
13.3.1未満のバージョン全て(12.x含む)で影響を受けます。

Due to insufficient validation of the redirect URL during miauth authentication in Misskey, arbitrary JavaScript can be executed when a user allows the linkage.
All versions below 13.3.1 (including 12.x) are affected.

Patches

13.3.1で修正されています。

This has been fixed in 13.3.1.

Workarounds

信頼できないアプリの連携を許可しない。

Do not allow authentication of untrusted apps.

Credits

RyotaK [email protected]

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda