Description
Mattermost fails to properly validate the origin of a websocket connection allowing a MITM attacker on Mattermost to access the websocket APIs.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost Server to versions v7.8.7, v7.9.5, v7.10.3 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-44231 | Mattermost fails to properly validate the origin of a websocket connection allowing a MITM attacker on Mattermost to access the websocket APIs. |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
Wed, 30 Oct 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-10-30T13:54:50.335Z
Reserved: 2023-07-10T12:32:13.548Z
Link: CVE-2023-3581
Updated: 2024-08-02T07:01:57.497Z
Status : Modified
Published: 2023-07-17T16:15:10.410
Modified: 2024-11-21T08:17:35.923
Link: CVE-2023-3581
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD