{"id":"BIT-mastodon-2023-42451","summary":"Mastodon Invalid Domain Name Normalization vulnerability","details":"Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 3.5.14, 4.0.10, 4.1.8, and 4.2.0, under certain circumstances, attackers can exploit a flaw in domain name normalization to spoof domains they do not own. Versions 3.5.14, 4.0.10, 4.1.8, and 4.2.0 contain a patch for this issue.","aliases":["CVE-2023-42451","GHSA-v3xf-c9qf-j667"],"modified":"2026-09-08T08:48:13.014189649Z","published":"2024-03-06T10:55:56.068Z","database_specific":{"cpes":["cpe:2.3:a:joinmastodon:mastodon:*:*:*:*:*:*:*:*","cpe:2.3:a:joinmastodon:mastodon:4.2.0:beta1:*:*:*:*:*:*","cpe:2.3:a:joinmastodon:mastodon:4.2.0:beta2:*:*:*:*:*:*","cpe:2.3:a:joinmastodon:mastodon:4.2.0:beta3:*:*:*:*:*:*","cpe:2.3:a:joinmastodon:mastodon:4.2.0:rc1:*:*:*:*:*:*"],"severity":"High"},"references":[{"type":"FIX","url":"https://github.com/mastodon/mastodon/commit/eeab3560fc0516070b3fb97e089b15ecab1938c8"},{"type":"ADVISORY","url":"https://github.com/mastodon/mastodon/security/advisories/GHSA-v3xf-c9qf-j667"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-42451"}],"affected":[{"package":{"name":"mastodon","ecosystem":"Bitnami","purl":"pkg:bitnami/mastodon"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.5.14"},{"introduced":"4.0.0"},{"fixed":"4.0.10"},{"introduced":"4.1.0"},{"fixed":"4.1.8"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/mastodon/BIT-mastodon-2023-42451.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}],"schema_version":"1.9.0"}