🔙 목록으로 돌아가기

CVE-2022-0432: Mastodon Prototype Pollution Vulnerability

TitleMastodon Prototype Pollution Vulnerability
Authorpikpikcu
SeverityMedium
ImpactRemote code execution
RemediationApply the latest security patches and updates provided by the Mastodon project to mitigate the vulnerability.
CVSS Score6.1
EPSS Score0.28093
CVE IDCVE-2022-0432
CWE IDCWE-1321
Tags cve cve2022 mastodon prototype huntr joinmastodon vuln

🔍 Vulnerability Description

The GitHub repository mastodon/mastodon prior to 3.5.0 contains a Prototype Pollution vulnerability.

🌐 HTTP Request

GET /embed.js HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.1 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-0432.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-0432.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A