Mastodon - Open Redirect
Mastodon version < 4.5.8, < 4.4.15, < 4.3.21 is vulnerable to unauthenticated Open Redirect vulnerability (CWE-601) exists in the /web/* route due to improper handling of URL-encoded path segments.
象牙塔社交网络PoC 已收录
CVSS—
共找到 2 条公开漏洞记录
Mastodon version < 4.5.8, < 4.4.15, < 4.3.21 is vulnerable to unauthenticated Open Redirect vulnerability (CWE-601) exists in the /web/* route due to improper handling of URL-encoded path segments.
The GitHub repository mastodon/mastodon prior to 3.5.0 contains a Prototype Pollution vulnerability.