{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-18T12:23:39.728","vulnerabilities":[{"cve":{"id":"CVE-2025-27399","sourceIdentifier":"security-advisories@github.com","published":"2025-02-27T18:15:30.380","lastModified":"2025-06-24T15:59:22.870","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Mastodon is a self-hosted, federated microblogging platform. In versions prior to 4.1.23, 4.2.16, and 4.3.4, when the visibility for domain blocks/reasons is set to \"users\" (localized English string: \"To logged-in users\"), users that are not yet approved can view the block reasons. Instance admins that do not want their domain blocks to be public are impacted. Versions 4.1.23, 4.2.16, and 4.3.4 fix the issue."},{"lang":"es","value":"Mastodon es una plataforma de microblogging federada y alojada por el usuario. En versiones anteriores a 4.1.23, 4.2.16 y 4.3.4, cuando la visibilidad de los bloqueos/razones de dominio está configurada en \"usuarios\" (cadena localizada en inglés: \"To logged-in users\"), los usuarios que aún no hayan sido aprobados pueden ver los motivos de bloqueo. Los administradores de instancias que no desean que sus bloqueos de dominio sean públicos se ven afectados. Las versiones 4.1.23, 4.2.16 y 4.3.4 solucionan el problema.\n"}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-200"},{"lang":"en","value":"CWE-285"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:joinmastodon:mastodon:*:*:*:*:*:*:*:*","versionEndExcluding":"4.1.23","matchCriteriaId":"9CFE3B6D-AA01-4B5F-BFDA-D206A457D55F"},{"vulnerable":true,"criteria":"cpe:2.3:a:joinmastodon:mastodon:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2.0","versionEndExcluding":"4.2.16","matchCriteriaId":"53633344-6503-4CB1-A5AD-3398E3819069"},{"vulnerable":true,"criteria":"cpe:2.3:a:joinmastodon:mastodon:*:*:*:*:*:*:*:*","versionStartIncluding":"4.3.0","versionEndExcluding":"4.3.4","matchCriteriaId":"97C4389D-7EB8-4E02-8DC8-DA1E39429AE9"}]}]}],"references":[{"url":"https://github.com/mastodon/mastodon/blob/93f0427b8a84faf68d5d02cdf9a26f98fae16f2b/app/controllers/api/v1/instances/domain_blocks_controller.rb#L33-L35","source":"security-advisories@github.com","tags":["Product"]},{"url":"https://github.com/mastodon/mastodon/blob/93f0427b8a84faf68d5d02cdf9a26f98fae16f2b/app/controllers/api/v1/instances/domain_blocks_controller.rb#L49-L51","source":"security-advisories@github.com","tags":["Product"]},{"url":"https://github.com/mastodon/mastodon/commit/6b519cfefa93a923b19d0f20c292c7185f8fd5f5","source":"security-advisories@github.com","tags":["Patch"]},{"url":"https://github.com/mastodon/mastodon/security/advisories/GHSA-94h4-fj37-c825","source":"security-advisories@github.com","tags":["Vendor Advisory"]}]}}]}