The Early Retirement GuideThe Early Retirement Guide
  • Personal Finance
  • Financial Planing
  • Investment
  • Startup
  • Small Businesses
  • Online
  • Trading
  • Crypto
  • Ebooks

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Rain Crypto Exchange Bags Financial Services Permission In Abu Dhabi

July 25, 2023

Ex-UBS exec Tom Naratil joins Lightyear Capital

July 25, 2023

Jack and Sam visit The Compound

July 25, 2023
Facebook Twitter Instagram
Sunday, December 3
The Early Retirement GuideThe Early Retirement Guide
Facebook Twitter Instagram
SUBSCRIBE
  • Personal Finance
  • Financial Planing
  • Investment
  • Startup
  • Small Businesses
  • Online
  • Trading
  • Crypto
  • Ebooks
The Early Retirement GuideThe Early Retirement Guide
Home»Online Business»Linode Security Digest July 3-July 9, 2023
Online Business

Linode Security Digest July 3-July 9, 2023

The Early Retirement GuideBy The Early Retirement GuideJuly 10, 2023No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Telegram Email
Linode-Security-Digest.jpeg
Share
Facebook Twitter LinkedIn Pinterest Email

Sign up for the “In the Node” newsletter

error .

Please reload the page and try again.

In this week’s digest, we discuss two critical vulnerabilities in Mastodon.

Mastodon Security Advisory

Background

Mastodon is a free, open source and widely used decentralized social network with microblogging capabilities. It is considered an open source and decentralized alternative to Twitter. Mastodon runs via independently managed nodes hosted by various entities on cloud hosting platforms such as Linode.

Vulnerability

Mastodon recently released a new version earlier this week that fixes multiple vulnerabilities, including two critical ones: CVE-2023-36460 and CVE-2023-36459.

CVE-2023-36460: arbitrary file creation with media attachments

This vulnerability is tracked as CVE-2023-36460 and is explained below GHSA-9928allows an attacker to create and overwrite files anywhere an installed Mastodon instance can access.

Vulnerable versions of Mastodon (versions 3.5.0 and later, and versions 3.5.9, 4.0.5, and earlier than 4.1.3) are unable to properly sanitize and neutralize special elements in pathnames, allowing external input to construct the pathname. This external input is intended to identify files or directories under a restricted directory. However, it is not restricted or sanitized to resolve only within this specified directory, allowing access and/or writing outside of the restricted directory via directory traversal. Such exploits can have devastating consequences, ranging from denial of service to remote code execution on Mastodon servers.

Because this vulnerability can be exploited by anyone who can post to the Mastodon server, the impact of this vulnerability is significant and is rated Critical. Additionally, Mastodon is a social media platform and has a large number of users who can post and execute exploits.

CVE-2023-36459: XSS with oEmbed preview cards

This vulnerability is tracked as CVE-2023-36459 and is explained below GHSA-ccm4is a cross-site scripting (XSS) vulnerability that allows an attacker to craft Mastodon oEmbed data to include arbitrary HTML in the oEmbed preview card, resulting in web browsers using untrusted source code. There are various risks associated with users operating the site.

Vulnerable versions of Mastodon (versions 1.3 and later, versions 3.5.9, 4.0.5, and earlier than 4.1.3) allow attackers to use oEmbed data to bypass the HTML sanitization process. These versions of her Mastodon do not correctly invalidate user-controllable inputs in the oEmbed preview card before being placed in the output as part of her web page served to other users. Thus, attacker-controlled HTML is presented to the user. This exploit introduces a vector of XSS payloads that, upon user interaction, can lead to the execution of untrusted malicious code on the user’s browser or machine.

This vulnerability is of high impact and severity because anyone who can create oEmbed data on the Mastodon server can exploit this vulnerability. Additionally, all members of the infected server are susceptible to attacks.

relief
  • Update your hosted Mastodon instance to version 4.1.3, 4.0.5, or 3.5.9.
  • Make sure the Mastodon server you are accessing is the latest version

Note: Mastodon can be hosted on Linodes by manual installation, or One-click marketplace app. However, these instances are not managed or maintained by Linode. Linode users are obligated to understand the risks and keep their installed software up to date. Learn more about. Mastodon Marketplace App Deployment Guide.

3July DigestJuly Linode Security
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
The Early Retirement Guide
  • Website

Related Posts

Women in Technology: Emily Davies

July 24, 2023

Need Help With VPS? Hostinger’s VPS AI Assistant to the Rescue!

July 24, 2023

Find WP Engine at WordCamp Europe!

July 23, 2023

DIY Functions: Comparing Serverless Toolsets

July 22, 2023

5 Tips for Picking the Best Load Balancer

July 21, 2023

Hostinger Employees Gather for the Summerfest Celebration

July 21, 2023
Add A Comment

Leave A Reply Cancel Reply

Don't Miss
Crypto

Rain Crypto Exchange Bags Financial Services Permission In Abu Dhabi

July 25, 2023

Abu Dhabi Global Markets has granted a Financial Services Permit (FSP) to cryptocurrency exchange platform…

Ex-UBS exec Tom Naratil joins Lightyear Capital

July 25, 2023

Jack and Sam visit The Compound

July 25, 2023

Top 5 accounting software providers for UK small businesses

July 25, 2023
Personal Finance

More Student Loan Forgiveness Coming for Longtime Borrowers

July 25, 2023

How To Make Friends In College

July 25, 2023

*HOT* Spend $20 on Groceries at Walgreens, Get $10 in Cash Rewards Today!

July 24, 2023

When To File For Unemployment If You Receive WARN Act Pay

July 24, 2023
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Demo

Subscribe to Updates

About Us
About Us

Our team of experts includes financial planners, investment professionals, and retired individuals who have achieved financial independence and are passionate about sharing their knowledge and experience. We believe that by providing comprehensive and actionable information, we can help individuals make informed decisions about their finances and achieve their goals faster.

Crypto

Rain Crypto Exchange Bags Financial Services Permission In Abu Dhabi

July 25, 2023

US Presidential Candidate Robert F. Kennedy Jr. To Speak At Mining Disrupt Bitcoin Conference

July 25, 2023

Judge in SBF’s criminal case proposes gag order, citing attempt to ‘influence public opinion’

July 24, 2023
New Comments
  • Hong Bernand on Sureshot Brewing: Bringing Joy Back to Beer
Facebook Twitter Instagram Pinterest
  • About Us
  • Contact Us
  • Advertise with us
  • Privacy Policy
  • Disclaimer
© 2023 The Early Retirement Guide. All Rights Reserved

Type above and press Enter to search. Press Esc to cancel.

We are using cookies to give you the best experience on our website.

You can find out more about which cookies we are using or switch them off in settings.

The Early Retirement Guide
Powered by  GDPR Cookie Compliance
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.

If you disable this cookie, we will not be able to save your preferences. This means that every time you visit this website you will need to enable or disable cookies again.