CVE-2023-3577: Limited blind SSRF to localhost/intranet in interactive dialog implementation
Mattermost fails to properly restrict requests to localhost/intranet during the interactive dialog, which could allow an attacker to perform a limited blind SSRF.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
mattermost-serverto a version that resolves this vulnerability.Fixed in 7.8.7 - Upgrade
Upgrade
mattermost-serverto a version that resolves this vulnerability.Fixed in 7.10.3
Event History
Frequently Asked Questions
What is CVE-2023-3577?
CVE-2023-3577 is a vulnerability in Mattermost that allows an attacker to perform a limited blind SSRF by exploiting the failure to properly restrict requests to localhost/intranet during the interactive dialog.
What is the severity of CVE-2023-3577?
CVE-2023-3577 has a severity of 4.3, which is considered medium.
How does CVE-2023-3577 affect Mattermost?
CVE-2023-3577 affects Mattermost versions between 7.8.0 and 7.8.7, as well as versions between 7.10.0 and 7.10.3 of Mattermost Server.
How can an attacker exploit CVE-2023-3577?
An attacker can exploit CVE-2023-3577 by sending unauthorized requests to localhost/intranet during the interactive dialog in Mattermost.
How can I fix CVE-2023-3577?
To fix CVE-2023-3577, it is recommended to upgrade Mattermost Server to a version beyond 7.10.3 or 7.8.7, depending on your current version.