Improper Authorization Affecting pixelfed/pixelfed package, versions >=0.10.4, <0.11.11


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of concept
EPSS
0.06% (26th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PHP-PIXELFEDPIXELFED-6244711
  • published13 Feb 2024
  • disclosed12 Feb 2024
  • creditEmelia Smith

Introduced: 12 Feb 2024

CVE-2024-25108  (opens in a new tab)
CWE-285  (opens in a new tab)

How to fix?

Upgrade pixelfed/pixelfed to version 0.11.11 or higher.

Overview

Affected versions of this package are vulnerable to Improper Authorization due to insufficient and improper checking of request authorizations. Attackers can gain access to functionalities beyond the intended user permissions, including administrative and moderator capabilities on the server.

Notes:

  1. This vulnerability affects every local user of a Pixelfed server, and can potentially affect the servers' ability to federate.

  2. Some user interaction is required to setup the conditions to be able to exercise the vulnerability, but the attacker could conduct this attack time-delayed manner, where user interaction is not actively required.

CVSS Scores

version 3.1