Vulnerabilities (CVE)

Filtered by vendor Join-lemmy
Filtered by product Lemmy
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-23649 1 Join-lemmy 1 Lemmy 2024-11-21 N/A 7.5 HIGH
Lemmy is a link aggregator and forum for the fediverse. Starting in version 0.17.0 and prior to version 0.19.1, users can report private messages, even when they're neither sender nor recipient of the message. The API response to creating a private message report contains the private message itself, which means any user can just iterate over message ids to (loudly) obtain all private messages of an instance. A user with instance admin privileges can also abuse this if the private message is remo ...

Show More