CVE-2023-28853 HIGH

CVE-2023-28853: Mastodon's blind LDAP injection in login allows the attacker to leak arbitrary attributes from LDAP database

Vendor Mastodon
Product mastodon
Weakness CWE-90 · LDAP injection
Published April 4, 2023
Last update February 13, 2025

CVSS base score

7.7/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

What the vulnerability does

01Description

Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authentication. Starting in version 2.5.0 and prior to versions 3.5.8, 4.0.4, and 4.1.2, the LDAP query made during login is insecure and the attacker can perform LDAP injection attack to leak arbitrary attributes from LDAP database. This issue is fixed in versions 3.5.8, 4.0.4, and 4.1.2.

Key dates

02Disclosure timeline

April 4, 2023 CVE published
February 13, 2025 Record updated