CVE-2023-49095: nexkey allows arbitrary users to impersonate any remote user due to missing signature validation

8.6 CVSS

Description

nexkey is a microblogging platform. Insufficient validation of ActivityPub requests received in inbox could allow any user to impersonate another user in certain circumstances. This issue has been patched in version 12.122.2.

Classification

CVE ID: CVE-2023-49095

CVSS Base Severity: HIGH

CVSS Base Score: 8.6

Affected Products

Vendor: nexryai

Product: nexkey

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.05% (probability of being exploited)

EPSS Percentile: 25.76% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://github.com/nexryai/nexkey/security/advisories/GHSA-fpxw-rw9v-2gmx
https://github.com/nexryai/nexkey/commit/b96da0eac5a1e75abba94cf926f1251842829bab

Timeline