Misskey is an open source, federated social media platform. Starting in version 12.109.0 and prior to version 2025.2.0-alpha.0, due to a lack of CSRF protection and the lack of proper security attributes in the authentication cookies of Bull's dashboard, some of the APIs of bull-board may be subject to CSRF attacks. There is a risk of this vulnerability being used for attacks with relatively large impact on availability and integrity, such as the ability to add arbitrary jobs. This vulnerability was fixed in 2025.2.0-alpha.0. As a workaround, block all access to the `/queue` directory with a web application firewall (WAF).
Metrics
Affected Vendors & Products
References
History
Wed, 12 Feb 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 11 Feb 2025 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Misskey is an open source, federated social media platform. Starting in version 12.109.0 and prior to version 2025.2.0-alpha.0, due to a lack of CSRF protection and the lack of proper security attributes in the authentication cookies of Bull's dashboard, some of the APIs of bull-board may be subject to CSRF attacks. There is a risk of this vulnerability being used for attacks with relatively large impact on availability and integrity, such as the ability to add arbitrary jobs. This vulnerability was fixed in 2025.2.0-alpha.0. As a workaround, block all access to the `/queue` directory with a web application firewall (WAF). | |
Title | Misskey CSRF vulnerability due to insecure configuration of authentication cookie attributes | |
Weaknesses | CWE-1275 CWE-352 CWE-614 |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-02-11T15:20:29.237Z
Updated: 2025-02-12T15:51:14.989Z
Reserved: 2025-01-27T15:32:29.452Z
Link: CVE-2025-24897

Updated: 2025-02-12T15:50:55.448Z

Status : Received
Published: 2025-02-11T16:15:51.610
Modified: 2025-02-11T16:15:51.610
Link: CVE-2025-24897

No data.