First published: Mon Jul 17 2023(Updated: )
Mattermost fails to properly validate markdown, allowing an attacker to crash the server via a specially crafted markdown input.
Credit: responsibledisclosure@mattermost.com responsibledisclosure@mattermost.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mattermost Mattermost Server | >=7.8.0<7.8.7 | |
Mattermost Mattermost Server | >=7.9.0<7.9.5 | |
Mattermost Mattermost Server | >=7.10.0<7.10.3 |
Update Mattermost to versions v7.8.7, v7.9.5, v7.10.3 or higher
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this Mattermost vulnerability is CVE-2023-3593.
The severity of CVE-2023-3593 is medium with a CVSS score of 6.5.
Mattermost fails to properly validate markdown, which allows an attacker to crash the server through a specially crafted markdown input.
Mattermost Server versions 7.8.0 through 7.8.7, 7.9.0 through 7.9.5, and 7.10.0 through 7.10.3 are affected by CVE-2023-3593.
To fix CVE-2023-3593 in Mattermost Server, it is recommended to update to a version beyond the affected range (7.8.7 to 7.8.0, 7.9.5 to 7.9.0, and 7.10.3 to 7.10.0) and apply any available security updates.