Mattermost fails to properly restrict requests to localhost/intranet during the interactive dialog, which could allow an attacker to perform a limited blind SSRF.
References
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published: 2023-07-17T15:18:07.871Z

Updated: 2024-08-02T07:01:56.833Z

Reserved: 2023-07-10T09:47:27.158Z

Link: CVE-2023-3577

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-07-17T16:15:10.330

Modified: 2023-07-27T20:04:24.007

Link: CVE-2023-3577

cve-icon Redhat

No data.