PT-2023-32883 · Mattermost · Mattermost

·

CVE-2023-7114

·

Publicado

2023-12-29

·

Atualizado

2024-01-05

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mattermost versions 2.10.0 and earlier
Description The issue allows an attacker to perform CSRF attacks against the server due to the failure to sanitize deeplink paths.
Recommendations For Mattermost versions 2.10.0 and earlier, update to a version that sanitizes deeplink paths to prevent CSRF attacks. As a temporary workaround, consider restricting access to deeplink paths until a patch is available.

Correção

Path traversal

Special Elements Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-7114

Produtos afetados

Mattermost