CVE-2023-5876: Regex DoS from a malicious server enrolled in Desktop
Published Nov 2, 2023
·Updated
Mattermost fails to properly validate a RegExp built off the server URL path, allowing an attacker in control of an enrolled server to mount a Denial Of Service.
Affected Software
1 affected component
Mattermost Mattermost Desktop<5.5.1
Remediation
Information
Update Mattermost Desktop to versions v5.5.1 or higher.
Event History
Nov 2, 2023
CVE Published
via MITRE·08:26 AM
Data Sourced
via MITRE·08:26 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-5876?
CVE-2023-5876 is a vulnerability in Mattermost Desktop that allows an attacker in control of an enrolled server to mount a Denial of Service attack.
2
How does CVE-2023-5876 impact Mattermost Desktop?
CVE-2023-5876 impacts Mattermost Desktop by allowing an attacker to launch a Denial of Service attack.
3
What is the severity of CVE-2023-5876?
The severity of CVE-2023-5876 is Medium.
4
Which version of Mattermost Desktop is affected by CVE-2023-5876?
Mattermost Desktop version up to and excluding 5.5.1 is affected by CVE-2023-5876.
5
How can I fix CVE-2023-5876?
To fix CVE-2023-5876, update your Mattermost Desktop to a version higher than 5.5.1.