First published: Fri Jun 16 2023(Updated: )
Mattermost fails to unescape Markdown strings in a memory-efficient way, allowing an attacker to cause a Denial of Service by sending a message containing a large number of escaped characters.
Credit: responsibledisclosure@mattermost.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mattermost Mattermost | >=7.1.0<=7.1.9 | |
Mattermost Mattermost | >=7.8.0<=7.8.4 | |
Mattermost Mattermost | >=7.9.0<=7.9.3 | |
Mattermost Mattermost | =7.10.0 |
Update Mattermost to version 7.1.10, 7.8.5, 7.9.4, 7.10.1 or higher.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-2831 is a vulnerability in Mattermost that allows an attacker to cause a Denial of Service by sending a message containing a large number of escaped characters.
Mattermost fails to unescape Markdown strings in a memory-efficient way.
The severity of CVE-2023-2831 is medium, with a severity value of 6.5.
Mattermost versions 7.1.0 to 7.1.9, 7.8.0 to 7.8.4, 7.9.0 to 7.9.3, and 7.10.0 are affected by CVE-2023-2831.
To fix CVE-2023-2831, update Mattermost to a version that is not affected by the vulnerability. Refer to the Mattermost security updates page for more information.