Mastodon's rate-limits are missing on `/auth/setup`
CVE-2025-27157
5.3MEDIUM
Key Information:
- Vendor
- Mastodon
- Status
- Mastodon
- Vendor
- CVE Published:
- 27 February 2025
Summary
Mastodon is a self-hosted, federated microblogging platform. Starting in version 4.2.0 and prior to versions 4.2.16 and 4.3.4, the rate limits are missing on /auth/setup
. Without those rate limits, an attacker can craft requests that will send an email to an arbitrary addresses. Versions 4.2.16 and 4.3.4 fix the issue.
Affected Version(s)
mastodon >= 4.2.0, < 4.2.16 < 4.2.0, 4.2.16
mastodon >= 4.3.0, < 4.3.4 < 4.3.0, 4.3.4
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved