CVE-2023-2793: Stack exhaustion in PreparePostForClientWithEmbedsAndImages
Published Jun 16, 2023
·Updated
Mattermost fails to validate links on external websites when constructing a preview for a linked website, allowing an attacker to cause a denial-of-service by a linking to a specially crafted webpage in a message.
Affected Software
3 affected components
Mattermost Mattermost>=7.8.0<=7.8.3
Mattermost Mattermost>=7.9.0<=7.9.2
Mattermost Mattermost=7.10.0
Remediation
Information
Update Mattermost to version v7.8.3, v7.9.2, 7.10.1 or higher.
Event History
Jun 16, 2023
CVE Published
via MITRE·09:02 AM
Data Sourced
via MITRE·09:02 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID for this issue is CVE-2023-2793.
2
What is the severity of CVE-2023-2793?
The severity of CVE-2023-2793 is medium.
3
How does Mattermost fail to validate links on external websites?
Mattermost fails to validate links on external websites when constructing a preview for a linked website.
4
What is the impact of CVE-2023-2793?
The vulnerability allows an attacker to cause a denial-of-service by linking to a specially crafted webpage in a message.
5
How can I fix CVE-2023-2793?
To fix CVE-2023-2793, update your Mattermost installation to a version that includes the security updates provided by the vendor.