PT-2023-32883 · Mattermost · Mattermost

Doyensec

·

Published

2023-12-29

·

Updated

2024-01-05

·

CVE-2023-7114

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mattermost versions 2.10.0 and earlier
Description The issue allows an attacker to perform CSRF attacks against the server due to the failure to sanitize deeplink paths.
Recommendations For Mattermost versions 2.10.0 and earlier, update to a version that sanitizes deeplink paths to prevent CSRF attacks. As a temporary workaround, consider restricting access to deeplink paths until a patch is available.

Fix

Path traversal

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2023-7114

Affected Products

Mattermost