CVE-2023-2797: Path traversal in GitHub plugin's code preview feature
Mattermost fails to sanitize code permalinks, allowing an attacker to preview code from private repositories by posting a specially crafted permalink on a channel.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-2797?
CVE-2023-2797 is a vulnerability in Mattermost that allows an attacker to preview code from private repositories by posting a specially crafted permalink on a channel.
How does Mattermost fail to sanitize code permalinks?
Mattermost fails to properly sanitize code permalinks, allowing an attacker to exploit the vulnerability.
Which versions of Mattermost are affected by CVE-2023-2797?
Versions between 7.1.0 and 7.1.9, versions between 7.8.0 and 7.8.4, and version 7.10.0 of Mattermost are affected by CVE-2023-2797.
What is the severity of CVE-2023-2797?
CVE-2023-2797 has a severity rating of 6.5 (medium).
How can I fix CVE-2023-2797?
To fix CVE-2023-2797, it is recommended to update Mattermost to a version that has patched the vulnerability. Refer to the vendor's security updates for more information.