Skip to content

XSS vulnerability using authentication callback

High
syuilo published GHSA-cc6r-chgr-8r5m Feb 22, 2023

Package

No package listed

Affected versions

< 13.3.1

Patched versions

13.3.1

Description

Impact

Misskeyのmiauth認証時において、リダイレクト先URLの検証が不十分なため、ユーザーが連携を許可した際に任意のJavaScriptを実行できます。
13.3.1未満のバージョン全て(12.x含む)で影響を受けます。

Due to insufficient validation of the redirect URL during miauth authentication in Misskey, arbitrary JavaScript can be executed when a user allows the linkage.
All versions below 13.3.1 (including 12.x) are affected.

Patches

13.3.1で修正されています。

This has been fixed in 13.3.1.

Workarounds

信頼できないアプリの連携を許可しない。

Do not allow authentication of untrusted apps.

Severity

High

CVE ID

CVE-2023-24810

Weaknesses

No CWEs

Credits