CVE-2024-52590

Misskey is an open source, federated social media platform. In affected versions missing validation in `ApRequestService.signedGet` allows an attacker to create fake user profiles that appear to be from a different instance than the one where they actually exist. These profiles can be used to impersonate existing users from the target instance. Vulnerable Misskey instances will accept spoofed users as valid, allowing an attacker to impersonate users on another instance. Attackers have full control of the spoofed user and can post, renote, or otherwise interact like a real account. This issue has been addressed in version 2024.11.0-alpha.3. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:misskey:misskey:*:*:*:*:*:*:*:*
cpe:2.3:a:misskey:misskey:2024.8.0:rc3:*:*:*:*:*:*
cpe:2.3:a:misskey:misskey:2024.8.0:rc4:*:*:*:*:*:*
cpe:2.3:a:misskey:misskey:2024.8.0:rc5:*:*:*:*:*:*
cpe:2.3:a:misskey:misskey:2024.11.0:alpha0:*:*:*:*:*:*
cpe:2.3:a:misskey:misskey:2024.11.0:alpha1:*:*:*:*:*:*
cpe:2.3:a:misskey:misskey:2024.11.0:alpha2:*:*:*:*:*:*

History

26 Nov 2025, 15:48

Type Values Removed Values Added
References () https://github.com/misskey-dev/misskey/security/advisories/GHSA-7vgr-p3vc-p4h2 - () https://github.com/misskey-dev/misskey/security/advisories/GHSA-7vgr-p3vc-p4h2 - Third Party Advisory
First Time Misskey misskey
Misskey
Summary
  • (es) Misskey es una plataforma de redes sociales federada de código abierto. En las versiones afectadas, la falta de validación en `ApRequestService.signedGet` permite a un atacante crear perfiles de usuario falsos que parecen ser de una instancia diferente a la que realmente existen. Estos perfiles se pueden usar para hacerse pasar por usuarios existentes de la instancia de destino. Las instancias vulnerables de Misskey aceptarán a los usuarios falsificados como válidos, lo que permite a un atacante hacerse pasar por usuarios de otra instancia. Los atacantes tienen control total del usuario falsificado y pueden publicar, volver a anotar o interactuar de otro modo como si fuera una cuenta real. Este problema se ha solucionado en la versión 2024.11.0-alpha.3. Se recomienda a los usuarios que actualicen. No se conocen workarounds para esta vulnerabilidad.
CPE cpe:2.3:a:misskey:misskey:2024.8.0:rc5:*:*:*:*:*:*
cpe:2.3:a:misskey:misskey:2024.11.0:alpha0:*:*:*:*:*:*
cpe:2.3:a:misskey:misskey:2024.11.0:alpha1:*:*:*:*:*:*
cpe:2.3:a:misskey:misskey:*:*:*:*:*:*:*:*
cpe:2.3:a:misskey:misskey:2024.8.0:rc3:*:*:*:*:*:*
cpe:2.3:a:misskey:misskey:2024.8.0:rc4:*:*:*:*:*:*
cpe:2.3:a:misskey:misskey:2024.11.0:alpha2:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

18 Dec 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-18 20:15

Updated : 2025-11-26 15:48


NVD link : CVE-2024-52590

Mitre link : CVE-2024-52590

CVE.ORG link : CVE-2024-52590


JSON object : View

Products Affected

misskey

  • misskey
CWE
CWE-20

Improper Input Validation