PKSA-bgxg-jhn7-yhxd Security Advisory
-
[CRITICAL] Pixelfed doesn't check OAuth Scopes in API routes, giving elevated permissions
PKSA-bgxg-jhn7-yhxd CVE-2024-25108 GHSA-gccq-h3xj-jgvf
Affected package: pixelfed/pixelfed
Affected version: >=0.10.4,<0.11.11
Reported by:
GitHub