CVE-2023-2808: Lack of URL normalization allows rendering previews for disallowed domains
Mattermost fails to normalize UTF confusable characters when determining if a preview should be generated for a hyperlink, allowing an attacker to trigger link preview on a disallowed domain using a specially crafted link.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-2808?
CVE-2023-2808 is a vulnerability in Mattermost that allows an attacker to trigger a link preview on a disallowed domain using a specially crafted link.
How does Mattermost fail to normalize UTF confusable characters?
Mattermost fails to normalize UTF confusable characters when determining if a preview should be generated for a hyperlink.
What is the severity of CVE-2023-2808?
CVE-2023-2808 has a severity rating of medium (5.3).
Which versions of Mattermost are affected by CVE-2023-2808?
Mattermost versions 5.34.0 to 7.1.9, 7.2.0 to 7.8.4, and 7.9.0 to 7.9.3 are affected by CVE-2023-2808.
How can the CVE-2023-2808 vulnerability be fixed?
To fix the CVE-2023-2808 vulnerability, it is recommended to update Mattermost to a version that is not affected by the vulnerability.