Mastodon is a self-hosted, federated microblogging platform. In versions prior to 4.1.23, 4.2.16, and 4.3.4, when the visibility for domain blocks/reasons is set to "users" (localized English string: "To logged-in users"), users that are not yet approved can view the block reasons. Instance admins that do not want their domain blocks to be public are impacted. Versions 4.1.23, 4.2.16, and 4.3.4 fix the issue.
Metrics
Affected Vendors & Products
References
History
Tue, 04 Mar 2025 03:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 27 Feb 2025 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Mastodon is a self-hosted, federated microblogging platform. In versions prior to 4.1.23, 4.2.16, and 4.3.4, when the visibility for domain blocks/reasons is set to "users" (localized English string: "To logged-in users"), users that are not yet approved can view the block reasons. Instance admins that do not want their domain blocks to be public are impacted. Versions 4.1.23, 4.2.16, and 4.3.4 fix the issue. | |
Title | Mastodon's domain blocks & rationales ignore user approval when visibility set as "users" | |
Weaknesses | CWE-200 CWE-285 |
|
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-27T17:59:31.801Z
Reserved: 2025-02-24T15:51:17.267Z
Link: CVE-2025-27399

Updated: 2025-02-27T17:59:26.913Z

Status : Received
Published: 2025-02-27T18:15:30.380
Modified: 2025-02-27T18:15:30.380
Link: CVE-2025-27399

No data.