Mastodon is a self-hosted, federated microblogging platform. Starting in version 4.2.0 and prior to versions 4.2.16 and 4.3.4, the rate limits are missing on `/auth/setup`. Without those rate limits, an attacker can craft requests that will send an email to an arbitrary addresses. Versions 4.2.16 and 4.3.4 fix the issue.
History

Tue, 24 Jun 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Joinmastodon
Joinmastodon mastodon
CPEs cpe:2.3:a:joinmastodon:mastodon:*:*:*:*:*:*:*:*
Vendors & Products Joinmastodon
Joinmastodon mastodon

Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Feb 2025 17:15:00 +0000

Type Values Removed Values Added
Description Mastodon is a self-hosted, federated microblogging platform. Starting in version 4.2.0 and prior to versions 4.2.16 and 4.3.4, the rate limits are missing on `/auth/setup`. Without those rate limits, an attacker can craft requests that will send an email to an arbitrary addresses. Versions 4.2.16 and 4.3.4 fix the issue.
Title Mastodon's rate-limits are missing on `/auth/setup`
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-02-27T17:12:39.043Z

Updated: 2025-02-27T18:10:00.154Z

Reserved: 2025-02-19T16:30:47.780Z

Link: CVE-2025-27157

cve-icon Vulnrichment

Updated: 2025-02-27T18:05:26.603Z

cve-icon NVD

Status : Analyzed

Published: 2025-02-27T17:15:16.867

Modified: 2025-06-24T15:59:59.633

Link: CVE-2025-27157

cve-icon Redhat

No data.