CVE-2023-28853

Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authentication. Starting in version 2.5.0 and prior to versions 3.5.8, 4.0.4, and 4.1.2, the LDAP query made during login is insecure and the attacker can perform LDAP injection attack to leak arbitrary attributes from LDAP database. This issue is fixed in versions 3.5.8, 4.0.4, and 4.1.2.

Scoring

Severity
HIGH
CVSS base score
7.7
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
EPSS probability
0.37%
CWE
CWE-90
Published
2023-04-04
Last modified
2026-03-13

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs