DEFCON 201 · @defcon201
792 followers · 7295 posts · Server hostux.social

From @MentalOutlaw:

In this video I discuss the recent security updates to Mastodon to fix critical security vulnerabilities that allowed for cross site scripting through oEmbed preview cards (CVE-2023-36459) and Arbitrary file creation through media attachments (CVE-2023-36460 AKA TootRoot) make sure the Mastodon instance you're using is on version 4.1.3 or later.

odysee.com/@AlphaNerd:8/mastod

#mastodon #fediverse #admin #cve #cve202336459 #cve202336460 #patch

Last updated 2 years ago

· @Wuzzy
365 followers · 104 posts · Server cyberplace.social

And the prize for the funniest name of a security vulnerability goes to: Tootroot! 🎉
(CVE-2023-36460)

#tootroot #security #mastodon #cve202336460

Last updated 2 years ago

WetzWetz' OnlyFriends 🥵🔞 · @markuswet
6 followers · 177 posts · Server toot.io
wakest is a 🦎 · @liaizon
4388 followers · 27999 posts · Server social.wake.st

Check in with your admins and server operators and make sure your instance is upgraded!

"Using carefully crafted media files, attackers can cause Mastodon's media processing code to create arbitrary files at any location"

github.com/mastodon/mastodon/s

#cve202336460

Last updated 2 years ago

cibyr · @cibyr
28 followers · 97 posts · Server omg.wtf.sh

Seems like you can have a rootin' tootin' good time with
HT @GossiTheDog

#cve202336460

Last updated 2 years ago

Kevin Beaumont · @GossiTheDog
29292 followers · 1207 posts · Server cyberplace.social

For anybody wondering what the Mastodon security issue is - CVE-2023-36460, you can send a toot which makes a webshell on instances that process it.

#cve202336460

Last updated 2 years ago