Description
Mattermost fails to unescape Markdown strings in a memory-efficient way, allowing an attacker to cause a Denial of Service by sending a message containing a large number of escaped characters.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost to version 7.1.10, 7.8.5, 7.9.4, 7.10.1 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-34282 | Mattermost fails to unescape Markdown strings in a memory-efficient way, allowing an attacker to cause a Denial of Service by sending a message containing a large number of escaped characters. |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates/ |
|
History
Fri, 06 Dec 2024 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-12-06T22:59:43.137Z
Reserved: 2023-05-22T09:30:20.884Z
Link: CVE-2023-2831
Updated: 2024-08-02T06:33:05.799Z
Status : Modified
Published: 2023-06-16T10:15:09.403
Modified: 2024-11-21T07:59:22.540
Link: CVE-2023-2831
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD