CVE-2023-2831: Denial of Service while unescaping a Markdown string
Mattermost fails to unescape Markdown strings in a memory-efficient way, allowing an attacker to cause a Denial of Service by sending a message containing a large number of escaped characters.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-2831?
CVE-2023-2831 is a vulnerability in Mattermost that allows an attacker to cause a Denial of Service by sending a message containing a large number of escaped characters.
How does Mattermost fail to unescape Markdown strings?
Mattermost fails to unescape Markdown strings in a memory-efficient way.
What is the severity of CVE-2023-2831?
The severity of CVE-2023-2831 is medium, with a severity value of 6.5.
Which versions of Mattermost are affected by CVE-2023-2831?
Mattermost versions 7.1.0 to 7.1.9, 7.8.0 to 7.8.4, 7.9.0 to 7.9.3, and 7.10.0 are affected by CVE-2023-2831.
How can I fix CVE-2023-2831?
To fix CVE-2023-2831, update Mattermost to a version that is not affected by the vulnerability. Refer to the Mattermost security updates page for more information.