First published: Fri Jun 16 2023(Updated: )
Mattermost fails to sanitize code permalinks, allowing an attacker to preview code from private repositories by posting a specially crafted permalink on a channel.
Credit: responsibledisclosure@mattermost.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mattermost Mattermost | >=7.1.0<=7.1.9 | |
Mattermost Mattermost | >=7.8.0<=7.8.4 | |
Mattermost Mattermost | =7.10.0 |
Update Mattermost to version v7.1.10, v7.8.5, v7.10.1 or higher.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-2797 is a vulnerability in Mattermost that allows an attacker to preview code from private repositories by posting a specially crafted permalink on a channel.
Mattermost fails to properly sanitize code permalinks, allowing an attacker to exploit the vulnerability.
Versions between 7.1.0 and 7.1.9, versions between 7.8.0 and 7.8.4, and version 7.10.0 of Mattermost are affected by CVE-2023-2797.
CVE-2023-2797 has a severity rating of 6.5 (medium).
To fix CVE-2023-2797, it is recommended to update Mattermost to a version that has patched the vulnerability. Refer to the vendor's security updates for more information.