Description
Mattermost fails to properly validate requests to the Calls plugin, allowing an attacker sending a request without a User Agent header to cause a panic and crash the Calls plugin

Published: 2023-11-06
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

 Update Mattermost Server to versions 7.8.12, 8.0.4, 8.1.3 or higher. Alternatively, upgrade the Calls plugin to 0.17.1 or higher. 

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-3066 Mattermost fails to properly validate requests to the Calls plugin, allowing an attacker sending a request without a User Agent header to cause a panic and crash the Calls plugin
Github GHSA Github GHSA GHSA-xvq6-h898-wcj8 Mattermost denial of service vulnerability
References
History

No history.

Subscriptions

Mattermost Mattermost
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2024-09-12T19:30:12.159Z

Reserved: 2023-11-06T15:14:58.458Z

Link: CVE-2023-5967

cve-icon Vulnrichment

Updated: 2024-08-02T08:14:25.127Z

cve-icon NVD

Status : Modified

Published: 2023-11-06T16:15:42.810

Modified: 2024-11-21T08:42:53.007

Link: CVE-2023-5967

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses