CVE-2023-29218
The Twitter Recommendation Algorithm through ec83d01 allows attackers to cause a denial of service (reduction of reputation score) by arranging for...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- April 03, 2023
- Published Date
- April 03, 2023
- Last Updated
- February 18, 2025
- Vendor
- n/a
- Product
- n/a
- Description
- The Twitter Recommendation Algorithm through ec83d01 allows attackers to cause a denial of service (reduction of reputation score) by arranging for multiple Twitter accounts to coordinate negative signals regarding a target account, such as unfollowing, muting, blocking, and reporting, as exploited in the wild in March and April 2023. NOTE: Vendor states that allowing users to unfollow, mute, block, and report tweets and accounts and the impact of these negative engagements on Twitter’s ranking algorithm is a conscious design decision, rather than a security vulnerability.
CVSS Scores
CVSS v3.1
7.5 - HIGH
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
SSVC Information
- Exploitation
- none
- Automatable
- Yes
- Technical Impact
- partial
Exploit Status
- Exploited in the Wild
- Yes (2023-04-03 00:00:00 UTC) Source
References
https://github.com/twitter/the-algorithm/issues/1386
https://twitter.com/elonmusk/status/1642324821324230657
https://steventey.com/blog/twitter-algorithm
https://twitter.com/aakashg0/status/1641976913165180929
https://twitter.com/Kaptain_Kobold/status/1642379706925477888
https://github.com/twitter/the-algorithm/tree/ec83d01dcaebf369444d75ed04b3625a0a645eb9
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CVE | 2023-04-03 00:00:00 UTC |
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Added to KEVIntel