Back to overview

CVE-2024-25108

CRITICAL Exploitation: PoC
9.9
CVSS 3.1
Description
Pixelfed is an open source photo sharing platform. When processing requests authorization was improperly and insufficiently checked, allowing attackers to access far more functionality than users intended, including to the administrative and moderator functionality of the Pixelfed server. This vulnerability affects every version of Pixelfed between v0.10.4 and v0.11.9, inclusive. A proof of concept of this vulnerability exists. This vulnerability affects every local user of a Pixelfed server, and can potentially affect the servers' ability to federate. Some user interaction is required to setup the conditions to be able to exercise the vulnerability, but the attacker could conduct this attack time-delayed manner, where user interaction is not actively required. This vulnerability has been addressed in version 0.11.11. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Metadata

CVE ID
CVE-2024-25108
State
PUBLISHED
Assigner
GitHub_M
Reserved
2024-02-05 14:14 UTC
Published
2024-02-12 20:05 UTC
Last updated
2025-05-07 21:03 UTC
Primary CWE
CWE-280
CWE-280: Improper Handling of Insufficient Permissions or Pr…
Vendor / Product
pixelfed / pixelfed
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
no
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
pixelfed pixelfed >= 0.10.4, < 0.11.11
Weakness (CWE)
CWESourceDescription
CWE-280 cna CWE-280: Improper Handling of Insufficient Permissions or Privileges
CWE-285 cna CWE-285: Improper Authorization
CWE-863 cna CWE-863: Incorrect Authorization
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L
References (2)
Back to overview