You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Missing validation in ApInboxService.update allows an attacker to modify the result of polls belonging to another user. No authentication is required, except for a valid signature from any actor on any remote instance.
Impact
Vulnerable Misskey instances will accept spoofed updates for remote polls. Local polls are unaffected.
Summary
Missing validation in
ApInboxService.update
allows an attacker to modify the result of polls belonging to another user. No authentication is required, except for a valid signature from any actor on any remote instance.Impact
Vulnerable Misskey instances will accept spoofed updates for remote polls. Local polls are unaffected.