Misskey is an open source, decentralized social media platform. Prior to version 2023.9.0, by editing the URL, a user can bypass the authentication of the Bull dashboard, which is the job queue management UI, and access it. Version 2023.9.0 contains a fix. There are no known workarounds.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: GitHub_M
Published: 2023-10-04T20:21:29.294Z
Updated: 2023-10-04T20:22:32.509Z
Reserved: 2023-09-22T14:51:42.339Z
Link: CVE-2023-43793
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-10-04T21:15:10.040
Modified: 2023-10-11T17:47:46.247
Link: CVE-2023-43793
JSON object: View
Redhat Information
No data.
CWE