VYPR
Unrated severityNVD Advisory· Published Nov 30, 2023· Updated Nov 27, 2024

nexkey allows arbitrary users to impersonate any remote user due to missing signature validation

CVE-2023-49095

Description

nexkey is a microblogging platform. Insufficient validation of ActivityPub requests received in inbox could allow any user to impersonate another user in certain circumstances. This issue has been patched in version 12.122.2.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.