Pixelfed before 0.12.5 allows anyone to follow private accounts and see private posts on other Fediverse servers. This affects users elsewhere in the Fediverse, if they otherwise have any followers from a Pixelfed instance.
History

Wed, 26 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Mar 2025 21:15:00 +0000

Type Values Removed Values Added
Description Pixelfed before 0.12.5 allows anyone to follow private accounts and see private posts on other Fediverse servers. Pixelfed before 0.12.5 allows anyone to follow private accounts and see private posts on other Fediverse servers. This affects users elsewhere in the Fediverse, if they otherwise have any followers from a Pixelfed instance.
References

Tue, 25 Mar 2025 21:00:00 +0000

Type Values Removed Values Added
Description pixelfed before 0.12.5 allows anyone to follow private accounts on other Fediverse servers. Pixelfed before 0.12.5 allows anyone to follow private accounts and see private posts on other Fediverse servers.
Weaknesses CWE-863
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Tue, 25 Mar 2025 20:45:00 +0000

Type Values Removed Values Added
Description pixelfed before 0.12.5 allows anyone to follow private accounts on other Fediverse servers.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-03-25T00:00:00.000Z

Updated: 2025-03-26T14:44:04.018Z

Reserved: 2025-03-25T00:00:00.000Z

Link: CVE-2025-30741

cve-icon Vulnrichment

Updated: 2025-03-26T14:44:00.534Z

cve-icon NVD

Status : Received

Published: 2025-03-25T21:15:43.527

Modified: 2025-03-25T21:15:43.527

Link: CVE-2025-30741

cve-icon Redhat

No data.