ActivityPub Username Enumeration

medium Web App Scanning Plugin ID 113978

Synopsis

ActivityPub Username Enumeration

Description

In certain ActivityPub WebFinger implementations it is possible to enumerate usernames (known as actors) on the API webfinger service using wildcard searches. This information may potentially expose personal profile addresses, identity service, telephone numbers, avatar selection or other informations via the api endpoint even if user listings and directories are disabled in the ActivityPub server application itself.

Solution

Block requests to the /.well-known/webfinger endpoint containing wildcard characters (*) at the server using a WAF for example.

See Also

https://docs.joinmastodon.org/spec/webfinger/

https://webfinger.net/

https://wordpress.org/plugins/webfinger/

Plugin Details

Severity: Medium

ID: 113978

Type: remote

Published: 8/29/2023

Updated: 8/29/2023

Scan Template: basic, full, pci, scan

Risk Information

VPR

Risk Factor: Low

Score: 2.2

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: Tenable

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CVSS Score Source: Tenable

Reference Information