CVE-2023-3581: WebSockets accept connections from HTTPS origin
Mattermost fails to properly validate the origin of a websocket connection allowing a MITM attacker on Mattermost to access the websocket APIs.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermost Serverto a version that resolves this vulnerability.Fixed in 7.10.3
Event History
Frequently Asked Questions
What is CVE-2023-3581?
CVE-2023-3581 is a vulnerability in Mattermost that allows a MITM attacker on Mattermost to access the websocket APIs.
How does Mattermost fail to validate the origin of a websocket connection?
Mattermost fails to properly validate the origin of a websocket connection, allowing a MITM attacker to access the websocket APIs.
What is the severity of CVE-2023-3581?
CVE-2023-3581 has a severity rating of 8.1 (high).
Which versions of Mattermost Server are affected by CVE-2023-3581?
Versions 7.8.0 to 7.8.7, 7.9.0 to 7.9.5, and 7.10.0 to 7.10.3 of Mattermost Server are affected by CVE-2023-3581.
How can I fix the CVE-2023-3581 vulnerability in Mattermost Server?
To fix the CVE-2023-3581 vulnerability in Mattermost Server, you should update to a version above 7.10.3, 7.9.5, or 7.8.7 depending on your current version.