Mattermost fails to normalize UTF confusable characters when determining if a preview should be generated for a hyperlink, allowing an attacker to trigger link preview on a disallowed domain using a specially crafted link.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mattermost | Mattermost | 5.34.0 (including) | 7.1.9 (excluding) |
Mattermost | Mattermost | 7.2.0 (including) | 7.8.4 (excluding) |
Mattermost | Mattermost | 7.9.0 (including) | 7.9.3 (excluding) |