First published: Mon Jul 17 2023(Updated: )
Mattermost Boards fail to properly validate a board link, allowing an attacker to crash a channel by posting a specially crafted boards link.
Credit: responsibledisclosure@mattermost.com responsibledisclosure@mattermost.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mattermost Mattermost Server | <7.8.7 | |
Mattermost Mattermost Server | >=7.9.0<7.9.5 | |
Mattermost Mattermost Server | >=7.10.0<7.10.3 |
Update Mattermost Server to versions v7.8.7, v7.9.5, v7.10.3 or higher.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-3585 is a vulnerability in Mattermost Boards that allows an attacker to crash a channel by posting a specially crafted boards link.
CVE-2023-3585 impacts Mattermost by allowing an attacker to crash a channel by posting a specially crafted boards link.
CVE-2023-3585 has a severity rating of 4.3, which is considered medium.
To fix CVE-2023-3585, make sure to update your Mattermost Server to a version that includes the necessary security patches.
You can find more information about CVE-2023-3585 and the necessary security updates on the Mattermost website.