Mattermost fails to properly validate requests to the Calls plugin, allowing an attacker sending a request without a User Agent header to cause a panic and crash the Calls plugin

Advisories
Source ID Title
EUVD EUVD EUVD-2023-3066 Mattermost fails to properly validate requests to the Calls plugin, allowing an attacker sending a request without a User Agent header to cause a panic and crash the Calls plugin
Github GHSA Github GHSA GHSA-xvq6-h898-wcj8 Mattermost denial of service vulnerability
Fixes

Solution

 Update Mattermost Server to versions 7.8.12, 8.0.4, 8.1.3 or higher. Alternatively, upgrade the Calls plugin to 0.17.1 or higher. 


Workaround

No workaround given by the vendor.

References
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2024-09-12T19:30:12.159Z

Reserved: 2023-11-06T15:14:58.458Z

Link: CVE-2023-5967

cve-icon Vulnrichment

Updated: 2024-08-02T08:14:25.127Z

cve-icon NVD

Status : Modified

Published: 2023-11-06T16:15:42.810

Modified: 2024-11-21T08:42:53.007

Link: CVE-2023-5967

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.