CVE-2023-3585: channel DoS by sharing a boards link
Mattermost Boards fail to properly validate a board link, allowing an attacker to crash a channel by posting a specially crafted boards link.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in v7.8.7 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in v7.9.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in v7.10.3
Event History
Frequently Asked Questions
What is CVE-2023-3585?
CVE-2023-3585 is a vulnerability in Mattermost Boards that allows an attacker to crash a channel by posting a specially crafted boards link.
How does CVE-2023-3585 impact Mattermost?
CVE-2023-3585 impacts Mattermost by allowing an attacker to crash a channel by posting a specially crafted boards link.
What is the severity of CVE-2023-3585?
CVE-2023-3585 has a severity rating of 4.3, which is considered medium.
How do I fix CVE-2023-3585?
To fix CVE-2023-3585, make sure to update your Mattermost Server to a version that includes the necessary security patches.
Where can I find more information about CVE-2023-3585?
You can find more information about CVE-2023-3585 and the necessary security updates on the Mattermost website.