CVE-2023-28853
Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authentication. Starting in version 2.5.0 and prior to versions 3.5.8, 4.0.4, and 4.1.2, the LDAP query made during login is insecure and the attacker can perform LDAP injection attack to leak arbitrary attributes from LDAP database. This issue is fixed in versions 3.5.8, 4.0.4, and 4.1.2.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.7
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
- EPSS probability
- 0.37%
- CWE
- CWE-90
- Published
- 2023-04-04
- Last modified
- 2026-03-13
Affected products
- mastodon mastodon
- mastodon mastodon
- mastodon mastodon
Weakness type
Related vulnerabilities
- CVE-2024-56841 — A vulnerability has been identified in Mendix LDAP (All versions < V1.1.2). Affected versions of the module are vulnerab
- CVE-2026-33289 — SuiterCRM has LDAP Filter Injection in Authentication Module
- CVE-2019-11277 — Volume Services is vulnerable to an LDAP injection attack
- CVE-2021-41232 — Improper Neutralization of Special Elements used in an LDAP Query
- CVE-2026-46619 — OpenAM Authentication Bypass via MSISDN LDAP Injection
- CVE-2020-5246 — LDAP injection vulnerability in Traccar GPS Tracking System
- CVE-2023-29050 — The optional "LDAP contacts provider" could be abused by privileged users to inject LDAP filter strings that allow to ac
- CVE-2026-41919 — Apache OFBiz: Authentication Bypass due to Improper Neutralization of LDAP Special Elements in DN Construction