CVE-2023-2808
29.05.2023, 10:15
Mattermost fails to normalize UTF confusable characters when determining if a preview should be generated for a hyperlink, allowing an attacker to trigger link preview on a disallowed domain using a specially crafted link.Enginsight
Vendor | Product | Version |
---|---|---|
mattermost | mattermost | 5.34.0 ≤ 𝑥 < 7.1.9 |
mattermost | mattermost | 7.2.0 ≤ 𝑥 < 7.8.4 |
mattermost | mattermost | 7.9.0 ≤ 𝑥 < 7.9.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration