CVE Vulnerabilities

CVE-2023-3581

Origin Validation Error

Published: Jul 17, 2023 | Modified: Jul 27, 2023
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Mattermost fails to properly validate the origin of a websocket connection allowing a MITM attacker on Mattermost to access the websocket APIs.

Weakness

The product does not properly verify that the source of data or communication is valid.

Affected Software

Name Vendor Start Version End Version
Mattermost_server Mattermost 7.8.0 (including) 7.8.7 (excluding)
Mattermost_server Mattermost 7.9.0 (including) 7.9.5 (excluding)
Mattermost_server Mattermost 7.10.0 (including) 7.10.3 (excluding)

References