Unrated severityNVD Advisory· Published Dec 27, 2023· Updated Aug 2, 2024
External apps using tokens issued by administrators and moderators can call admin APIs
CVE-2023-52077
Description
Nexkey is a lightweight fork of Misskey v12 optimized for small to medium size servers. Prior to 12.23Q4.5, Nexkey allows external apps using tokens issued by administrators and moderators to call admin APIs. This allows malicious third-party apps to perform operations such as updating server settings, as well as compromise object storage and email server credentials. This issue has been patched in 12.23Q4.5.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/mei23/misskey-v12/commit/78173e376f14fcc1987b02196f5538bf5b18225cmitrex_refsource_MISC
- github.com/misskey-dev/misskey/commit/5150053275594278e9eb23e72d98b16593c4c230mitrex_refsource_MISC
- github.com/nexryai/nexkey/commit/a4e4c9c47c5f84ec7ccd309bde59d4ae5d7e5a98mitrex_refsource_MISC
- github.com/nexryai/nexkey/security/advisories/GHSA-pjj7-7hcj-9cpcmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.