Description
Mattermost Boards fail to properly validate a board link, allowing an attacker to crash a channel by posting a specially crafted boards link.

Published: 2023-07-17
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update Mattermost Server to versions v7.8.7, v7.9.5, v7.10.3 or higher.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-44235 Mattermost Boards fail to properly validate a board link, allowing an attacker to crash a channel by posting a specially crafted boards link.
References
History

Mon, 21 Oct 2024 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Mattermost Mattermost Server
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2024-10-21T19:43:02.507Z

Reserved: 2023-07-10T13:44:28.891Z

Link: CVE-2023-3585

cve-icon Vulnrichment

Updated: 2024-08-02T07:01:57.036Z

cve-icon NVD

Status : Modified

Published: 2023-07-17T16:15:10.633

Modified: 2024-11-21T08:17:36.357

Link: CVE-2023-3585

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses