漏洞标题
Misskey的CVE-2024-52591补丁不完整导致联邦笔记伪造漏洞
漏洞描述信息
Misskey 是一个开源的、联合式的社交媒体平台。CVE-2024-52591 的补丁没有充分验证 ActivityPub 对象中的 `id` 和 `url` 字段之间的关系。攻击者可以伪造一个对象,在 `url` 字段中声称拥有权限,即使特定的 ActivityPub 对象类型要求在 `id` 字段中拥有权限。版本 2025.2.1 解决了该问题。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
漏洞类别
授权机制不正确
漏洞标题
Misskey's Incomplete Patch of CVE-2024-52591 Leads to Forgery of Federated Notes
漏洞描述信息
Misskey is an open source, federated social media platform. The patch for CVE-2024-52591 did not sufficiently validate the relation between the `id` and `url` fields of ActivityPub objects. An attacker can forge an object where they claim authority in the `url` field even if the specific ActivityPub object type require authority in the `id` field. Version 2025.2.1 addresses the issue.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:N
漏洞类别
源验证错误