6 results (0.002 seconds)

CVSS: 9.3EPSS: 0%CPEs: 1EXPL: 0

11 Feb 2025 — Concorde, formerly know as Nexkey, is a fork of the federated microblogging platform Misskey. Prior to version 12.25Q1.1, due to an improper implementation of the logout process, authentication credentials remain in cookies even after a user has explicitly logged out, which may allow an attacker to steal authentication tokens. This could have devastating consequences if a user with admin privileges is (or was) using a shared device. Users who have logged in on a shared device should go to Settings > Securit... • https://github.com/nexryai/concorde/commit/1f6ac9b289906083b132e4f9667a31a60ef83e4e • CWE-613: Insufficient Session Expiration •

CVSS: 8.6EPSS: 0%CPEs: 1EXPL: 0

11 Feb 2025 — Concorde, formerly know as Nexkey, is a fork of the federated microblogging platform Misskey. Due to a lack of CSRF countermeasures and improper settings of cookies for MediaProxy authentication, there is a vulnerability that allows MediaProxy authentication to be bypassed. In versions prior to 12.25Q1.1, the authentication cookie does not have the SameSite attribute. This allows an attacker to bypass MediaProxy authentication and load any image without restrictions under certain circumstances. In versions ... • https://github.com/nexryai/concorde/commit/2309b4a292828ddba4d57cf0e914bc433095871d • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 8.6EPSS: 0%CPEs: 1EXPL: 0

19 Dec 2024 — Altair is a fork of Misskey v12. Affected versions lack of request validation and lack of authentication in the image proxy for compressing and resizing remote files could allow attacks that could affect availability, such as by abnormally increasing the CPU usage of the server on which this software is running or placing a heavy load on the network it is using. This issue has been fixed in v12.24Q4.1. Users are advised to upgrade. There are no known workarounds for this vulnerability. • https://github.com/misskey-dev/misskey/security/advisories/GHSA-gq5q-c77c-v23600 • CWE-400: Uncontrolled Resource Consumption CWE-405: Asymmetric Resource Consumption (Amplification) •

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0

27 Dec 2023 — Nexkey is a lightweight fork of Misskey v12 optimized for small to medium size servers. Prior to 12.23Q4.5, Nexkey allows external apps using tokens issued by administrators and moderators to call admin APIs. This allows malicious third-party apps to perform operations such as updating server settings, as well as compromise object storage and email server credentials. This issue has been patched in 12.23Q4.5. Nexkey es una bifurcación liviana de Misskey v12 optimizada para servidores de tamaño pequeño y med... • https://github.com/mei23/misskey-v12/commit/78173e376f14fcc1987b02196f5538bf5b18225c • CWE-863: Incorrect Authorization •

CVSS: 8.6EPSS: 0%CPEs: 1EXPL: 0

30 Nov 2023 — nexkey is a microblogging platform. Insufficient validation of ActivityPub requests received in inbox could allow any user to impersonate another user in certain circumstances. This issue has been patched in version 12.122.2. nexkey es una plataforma de microblogging. Una validación insuficiente de las solicitudes de ActivityPub recibidas en la bandeja de entrada podría permitir que cualquier usuario se haga pasar por otro usuario en determinadas circunstancias. Este problema se solucionó en la versión 12.1... • https://github.com/nexryai/nexkey/commit/b96da0eac5a1e75abba94cf926f1251842829bab • CWE-20: Improper Input Validation •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

04 Oct 2023 — Nexkey is a fork of Misskey, an open source, decentralized social media platform. Prior to version 12.121.9, incomplete URL validation can allow users to bypass authentication for access to the job queue dashboard. Version 12.121.9 contains a fix for this issue. As a workaround, it may be possible to avoid this by blocking access using tools such as Cloudflare's WAF. Nexkey es un fork de Misskey, una plataforma de redes sociales descentralizada y de código abierto. • https://github.com/misskey-dev/misskey/security/advisories/GHSA-9fj2-gjcf-cqqc • CWE-287: Improper Authentication •