CVE-2023-2000: Unrestricted navigation due to unvalidated mattermost server redirection
Published May 2, 2023
·Updated
Mattermost Desktop App fails to validate a mattermost server redirection and navigates to an arbitrary website
Affected Software
1 affected component
Mattermost Mattermost Desktop<=5.2.2
Remediation
Information
Update Mattermost Desktop App to version v5.3 or higher.
Event History
May 2, 2023
CVE Published
via MITRE·08:57 AM
Data Sourced
via MITRE·08:57 AM
RemedyDescriptionSeverityWeakness
Data Sourced
09:15 AM
Description
Frequently Asked Questions
1
What is CVE-2023-2000?
CVE-2023-2000 is a vulnerability in the Mattermost Desktop App that allows for redirection to arbitrary websites.
2
How does CVE-2023-2000 affect Mattermost Desktop App?
CVE-2023-2000 affects Mattermost Desktop App by failing to validate server redirection, allowing users to be redirected to arbitrary websites.
3
What is the severity of CVE-2023-2000?
CVE-2023-2000 has a severity rating of medium with a CVSS score of 5.4.
4
Which version of Mattermost Desktop App is affected by CVE-2023-2000?
Mattermost Desktop App version 5.2.2 is affected by CVE-2023-2000.
5
How can I mitigate the vulnerability in Mattermost Desktop App?
To mitigate CVE-2023-2000, it is recommended to update to a patched version of Mattermost Desktop App when it becomes available.