CVE-2026-22246 (CNNVD-202601-1446)
中文标题:
Mastodon 安全漏洞
英文标题:
Local Mastodon users can enumerate and access severed relationships of every other local user
漏洞描述
中文描述:
Mastodon是Mastodon开源的一款基于ActivityPub的开源社交网络服务器。 Mastodon 4.3.17之前版本、4.4.11之前版本和4.5.4之前版本存在安全漏洞,该漏洞源于缺少关系列表所有权检查,可能导致信息泄露。
英文描述:
Mastodon is a free, open-source social network server based on ActivityPub. Mastodon 4.3 added notifications of severed relationships, allowing end-users to inspect the relationships they lost as the result of a moderation action. The code allowing users to download lists of severed relationships for a particular event fails to check the owner of the list before returning the lost relationships. Any registered local user can access the list of lost followers and followed users caused by any severance event, and go through all severance events this way. The leaked information does not include the name of the account which has lost follows and followers. This has been fixed in Mastodon v4.3.17, v4.4.11 and v4.5.4.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| mastodon | mastodon | < 4.3.17 | - | - |
cpe:2.3:a:mastodon:mastodon:<_4.3.17:*:*:*:*:*:*:*
|
| mastodon | mastodon | >= 4.4.0-beta.1, < 4.4.11 | - | - |
cpe:2.3:a:mastodon:mastodon:>=_4.4.0-beta.1,_<_4.4.11:*:*:*:*:*:*:*
|
| mastodon | mastodon | >= 4.5.0-beta.1, < 4.5.4 | - | - |
cpe:2.3:a:mastodon:mastodon:>=_4.5.0-beta.1,_<_4.5.4:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
cve.org
cve.org
cve.org
CVSS评分详情
3.1 (cna)
MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2026-22246 |
2026-01-09 02:02:08 | 2026-01-12 02:12:38 |
| NVD | nvd_CVE-2026-22246 |
2026-01-09 03:00:10 | 2026-01-12 02:28:17 |
| CNNVD | cnnvd_CNNVD-202601-1446 |
2026-01-11 06:15:11 | 2026-01-12 02:38:14 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 其他
- cnnvd_id: 未提取 -> CNNVD-202601-1446
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- data_sources: ['cve'] -> ['cve', 'nvd']