CVE-2023-3593: Server crash via a specially crafted markdown input
Mattermost fails to properly validate markdown, allowing an attacker to crash the server via a specially crafted markdown input.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in v7.8.7Patch Server crash via a specially crafted markdown input - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in v7.9.5Patch Server crash via a specially crafted markdown input - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in v7.10.3Patch Server crash via a specially crafted markdown input
Event History
Frequently Asked Questions
What is the vulnerability ID of this Mattermost vulnerability?
The vulnerability ID of this Mattermost vulnerability is CVE-2023-3593.
What is the severity of CVE-2023-3593?
The severity of CVE-2023-3593 is medium with a CVSS score of 6.5.
How does Mattermost fail to properly validate markdown?
Mattermost fails to properly validate markdown, which allows an attacker to crash the server through a specially crafted markdown input.
Which versions of Mattermost Server are affected by CVE-2023-3593?
Mattermost Server versions 7.8.0 through 7.8.7, 7.9.0 through 7.9.5, and 7.10.0 through 7.10.3 are affected by CVE-2023-3593.
How can I fix CVE-2023-3593 in Mattermost Server?
To fix CVE-2023-3593 in Mattermost Server, it is recommended to update to a version beyond the affected range (7.8.7 to 7.8.0, 7.9.5 to 7.9.0, and 7.10.3 to 7.10.0) and apply any available security updates.