CVE-2023-2000
published 2023-05-02CVE-2023-2000: Mattermost Desktop App fails to validate a mattermost server redirection and navigates to an arbitrary website
PriorityP426medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.36%
28.4th percentile
Mattermost Desktop App fails to validate a mattermost server redirection and navigates to an arbitrary website
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome_chrome | — | — | |
| linux | linux_kernel | >= 3.5.0 < 5.10.192 | 5.10.192 |
| linux | linux_kernel | >= 5.11.0 < 5.15.128 | 5.15.128 |
| linux | linux_kernel | >= 5.16.0 < 6.1.47 | 6.1.47 |
| linux | linux_kernel | >= 6.2.0 < 6.4.12 | 6.4.12 |
| mattermost | mattermost | <= 5.2.2 | — |
| mattermost | mattermost_desktop | <= 5.2.2 | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
ring-buffer: Do not swap cpu_buffer during resize process
osv·2025-10-22
CVE-2023-53718 ring-buffer: Do not swap cpu_buffer during resize process
ring-buffer: Do not swap cpu_buffer during resize process
In the Linux kernel, the following vulnerability has been resolved:
ring-buffer: Do not swap cpu_buffer during resize process
When ring_buffer_swap_cpu was called during resize process,
the cpu buffer was swapped in the middle, resulting in incorrect state.
Continuing to run in the wrong state will result in oops.
This issue can be easily reproduced using the following two scripts:
/tmp # cat test1.sh
//#! /bin/sh
for i in `seq 0 100000`
do
echo 2000 > /sys/kernel/debug/tracing/buffer_size_kb
sleep 0.5
echo 5000 > /sys/kernel/debug/tracing/buffer_size_kb
sleep 0.5
done
/tmp # cat test2.sh
//#! /bin/sh
for i in `seq 0 100000`
do
echo irqsoff > /sys/kernel/debug/tracing/current_tracer
sleep 1
echo nop > /sys/kernel/debug/tracing/c
GHSA
GHSA-c2w9-hhfq-2xq9: Mattermost Desktop App fails to validate a mattermost server redirection and navigates to an arbitrary website
ghsa_unreviewed·2023-07-06
CVE-2023-2000 [MEDIUM] CWE-601 GHSA-c2w9-hhfq-2xq9: Mattermost Desktop App fails to validate a mattermost server redirection and navigates to an arbitrary website
Mattermost Desktop App fails to validate a mattermost server redirection and navigates to an arbitrary website
Chrome
Stable Channel Update for Desktop: CVE-2025-0440
vendor_chrome·2025-01-14·CVSS 6.5
CVE-2025-0440 [MEDIUM] Stable Channel Update for Desktop: CVE-2025-0440
Stable Channel Update for Desktop
CVE-2025-0440: Inappropriate implementation in Fullscreen. Reported by Umar Farooq on 2023-07-22 [$2000][ 368628042 ] Medium CVE-2025-0441: Inappropriate implementation in Fenced Frames
Reported by someoneverycurious on 2024-09-21 [$2000][ 40940854 ] Medium CVE-2025-0442: Inappropriate implementation in Payments
Severity: medium
Chrome
Stable Channel Update for Desktop: CVE-2024-3845
vendor_chrome·2024-04-16·CVSS 4.3
CVE-2024-3845 [LOW] Stable Channel Update for Desktop: CVE-2024-3845
Stable Channel Update for Desktop
CVE-2024-3845: Inappropriate implementation in Network. Reported by Daniel Baulig on 2024-02-03 [$2000][ 40064754 ] Low CVE-2024-3846: Inappropriate implementation in Prompts
Reported by Ahmed ElMasry on 2023-05-23 [$1000][ 328690293 ] Low CVE-2024-3847: Insufficient policy enforcement in WebUI
Severity: low
Chrome
Stable Channel Update for Desktop: CVE-2024-2629
vendor_chrome·2024-03-19·CVSS 4.3
CVE-2024-2629 [MEDIUM] Stable Channel Update for Desktop: CVE-2024-2629
Stable Channel Update for Desktop
CVE-2024-2629: Incorrect security UI in iOS. Reported by Muneaki Nishimura (nishimunea) on 2024-01-02 [$1000][ 41481877 ] Medium CVE-2024-2630: Inappropriate implementation in iOS
Reported by James Lee (@Windowsrcer) on 2023-12-07 [$2000][ 41495878 ] Low CVE-2024-2631: Inappropriate implementation in iOS
Severity: medium
Chrome
Stable Channel Update for Desktop: CVE-2023-6510
vendor_chrome·2023-12-05·CVSS 8.8
CVE-2023-6510 [MEDIUM] Stable Channel Update for Desktop: CVE-2023-6510
Stable Channel Update for Desktop
CVE-2023-6510: Use after free in Media Capture. Reported by [pwn2car] on 2023-09-08 [$2000][ 1478613 ] Low CVE-2023-6511: Inappropriate implementation in Autofill
Reported by Ahmed ElMasry on 2023-09-04 [$5000][ 40069571 ] Low CVE-2024-3175: Insufficient data validation in Extensions
Severity: medium
Chrome
Stable Channel Update for Desktop: CVE-2023-5485
vendor_chrome·2023-10-10·CVSS 4.3
CVE-2023-5485 [LOW] Stable Channel Update for Desktop: CVE-2023-5485
Stable Channel Update for Desktop
CVE-2023-5485: Inappropriate implementation in Autofill. Reported by Ahmed ElMasry on 2022-12-02 [$2000][ 1472404 ] Low CVE-2023-5478: Inappropriate implementation in Autofill
Reported by Shaheen Fazim on 2023-06-15 [$3000][ 1472558 ] Low CVE-2023-5477: Inappropriate implementation in Installer
Severity: low
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2023-4904
vendor_chrome·2023-09-26·CVSS 4.3
CVE-2023-4904 [MEDIUM] Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2023-4904
Stable Channel Update for ChromeOS / ChromeOS Flex
CVE-2023-4904: Insufficient policy enforcement in Downloads. Reported by Tudor Enache @tudorhacks on 2023-06-09 [$6000][ 1449874 ] Low CVE-2023-4906: Insufficient policy enforcement in Autofill
Reported by Ahmed ElMasry on 2023-05-30 [$2000][ 1451543 ] Low CVE-2023-4908: Inappropriate implementation in Picture in Picture
Severity: medium
Chrome
Stable Channel Update for Desktop: CVE-2023-4900
vendor_chrome·2023-09-12·CVSS 4.3
CVE-2023-4900 [MEDIUM] Stable Channel Update for Desktop: CVE-2023-4900
Stable Channel Update for Desktop
CVE-2023-4900: Inappropriate implementation in Custom Tabs. Reported by Levit Nudi from Kenya on 2023-04-06 [$3000][ 1459281 ] Medium CVE-2023-4901: Inappropriate implementation in Prompts
Reported by Kang Ali on 2023-06-29 [$2000][ 1454515 ] Medium CVE-2023-4902: Inappropriate implementation in Input
Severity: medium
Chrome
Stable Channel Update for Desktop: CVE-2023-7012
vendor_chrome·2023-09-12·CVSS 4.3
CVE-2023-7012 [MEDIUM] Stable Channel Update for Desktop: CVE-2023-7012
Stable Channel Update for Desktop
CVE-2023-7012: Insufficient data validation in Permission Prompts. Reported by koocola (@alo_cook) and Nan Wang (@eternalsakura13) of 360 Alpha Lab on 2022-10-28 [$6000][ 1449874 ] Low CVE-2023-4906: Insufficient policy enforcement in Autofill
Reported by Ahmed ElMasry on 2023-05-30 [$2000][ 1462104 ] Low CVE-2023-4907: Inappropriate implementation in Intents
Severity: medium
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2023-4358
vendor_chrome·2023-08-25·CVSS 8.8
CVE-2023-4358 [MEDIUM] Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2023-4358
Stable Channel Update for ChromeOS / ChromeOS Flex
CVE-2023-4358: Use after free in DNS. Reported by Weipeng Jiang (@Krace) of VRI on 2023-07-20 [$2000][ 1443722 ] Medium CVE-2023-4359: Inappropriate implementation in App Launcher
Reported by @retsew0x01 on 2023-05-09 [$2000][ 1462723 ] Medium CVE-2023-4360: Inappropriate implementation in Color
Severity: medium
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2023-4349
vendor_chrome·2023-08-25·CVSS 8.8
CVE-2023-4349 [HIGH] Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2023-4349
Stable Channel Update for ChromeOS / ChromeOS Flex
CVE-2023-4349: Use after free in Device Trust Connectors. Reported by Weipeng Jiang (@Krace) of VRI on 2023-06-27 [$3000][ 1454817 ] High CVE-2023-4350: Inappropriate implementation in Fullscreen
Reported by Khiem Tran (@duckhiem) on 2023-06-14 [$2000][ 1465833 ] High CVE-2023-4351: Use after free in Network
Severity: high
Chrome
Stable Channel Update for Desktop: CVE-2023-4430
vendor_chrome·2023-08-22·CVSS 8.1
CVE-2023-4430 [HIGH] Stable Channel Update for Desktop: CVE-2023-4430
Stable Channel Update for Desktop
CVE-2023-4430: Use after free in Vulkan. Reported by Cassidy Kim(@cassidy6564) on 2023-08-02 [$3000][ 1469754 ] High CVE-2023-4429: Use after free in Loader
Reported by Anonymous on 2023-08-03 [$2000][ 1470477 ] High CVE-2023-4428: Out of bounds memory access in CSS
Severity: high
Chrome
Stable Channel Update for Desktop: CVE-2023-3727
vendor_chrome·2023-07-18·CVSS 8.8
CVE-2023-3727 [HIGH] Stable Channel Update for Desktop: CVE-2023-3727
Stable Channel Update for Desktop
CVE-2023-3727: Use after free in WebRTC. Reported by Cassidy Kim(@cassidy6564) on 2023-06-12 [$7000][ 1457421 ] High CVE-2023-3728: Use after free in WebRTC
Reported by Zhenghang Xiao (@Kipreyyy) on 2023-06-23 [$2000][ 1453465 ] High CVE-2023-3730: Use after free in Tab Groups
Severity: high
Chrome
Stable Channel Update for Desktop: CVE-2023-1231
vendor_chrome·2023-03-07·CVSS 4.3
CVE-2023-1231 [MEDIUM] Stable Channel Update for Desktop: CVE-2023-1231
Stable Channel Update for Desktop
CVE-2023-1231: Inappropriate implementation in Autofill. Reported by Kirtikumar Anandrao Ramchandani via Yan Zhu of Brave on 2021-11-30 [$3000][ 813542 ] Low CVE-2023-2314: Insufficient data validation in DevTools
Reported by Rob Wu on 2018-02-19 [$2000][ 1346924 ] Low CVE-2023-1232: Insufficient policy enforcement in Resource Timing
Severity: medium
Chrome
Stable Channel Update for Desktop: CVE-2023-1228
vendor_chrome·2023-03-07·CVSS 4.3
CVE-2023-1228 [MEDIUM] Stable Channel Update for Desktop: CVE-2023-1228
Stable Channel Update for Desktop
CVE-2023-1228: Insufficient policy enforcement in Intents. Reported by Axel Chong on 2022-09-18 [$2000][ 1160485 ] Medium CVE-2023-1229: Inappropriate implementation in Permission prompts
Reported by Thomas Orlita on 2020-12-20 [$2000][ 1404230 ] Medium CVE-2023-1230: Inappropriate implementation in WebApp Installs
Severity: medium
Chrome
Stable Channel Update for Desktop: CVE-2023-0696
vendor_chrome·2023-02-07·CVSS 8.8
CVE-2023-0696 [HIGH] Stable Channel Update for Desktop: CVE-2023-0696
Stable Channel Update for Desktop
CVE-2023-0696: Type Confusion in V8. Reported by Haein Lee at KAIST Hacking Lab on 2022-12-18 [$4000][ 1341541 ] High CVE-2023-0697: Inappropriate implementation in Full screen mode
Reported by Ahmed ElMasry on 2022-07-03 [$2000][ 1403573 ] High CVE-2023-0698: Out of bounds read in WebRTC
Severity: high
Chrome
Stable Channel Update for Desktop: CVE-2023-0702
vendor_chrome·2023-02-07·CVSS 8.8
CVE-2023-0702 [MEDIUM] Stable Channel Update for Desktop: CVE-2023-0702
Stable Channel Update for Desktop
CVE-2023-0702: Type Confusion in Data Transfer. Reported by Sri on 2022-04-14 [$1000][ 1405574 ] Medium CVE-2023-0703: Type Confusion in DevTools
Reported by raven at KunLun lab on 2023-01-07 [$2000][ 1385982 ] Low CVE-2023-0704: Insufficient policy enforcement in DevTools
Severity: medium
Chrome
Stable Channel Update for Desktop: CVE-2023-0699
vendor_chrome·2023-02-07·CVSS 8.8
CVE-2023-0699 [MEDIUM] Stable Channel Update for Desktop: CVE-2023-0699
Stable Channel Update for Desktop
CVE-2023-0699: Use after free in GPU. Reported by 7o8v and Cassidy Kim(@cassidy6564) on 2022-10-06 [$3000][ 1393732 ] Medium CVE-2023-0700: Inappropriate implementation in Download
Reported by Axel Chong on 2022-11-26 [$2000][ 1405123 ] Medium CVE-2023-0701: Heap buffer overflow in WebUI
Severity: medium
Chrome
Stable Channel Update for Desktop: CVE-2023-0134
vendor_chrome·2023-01-10·CVSS 8.8
CVE-2023-0134 [MEDIUM] Stable Channel Update for Desktop: CVE-2023-0134
Stable Channel Update for Desktop
CVE-2023-0134: Use after free in Cart. Reported by Chaoyuan Peng (@ret2happy) on 2022-11-17 [$2500][ 1385831 ] Medium CVE-2023-0135: Use after free in Cart
Reported by Chaoyuan Peng (@ret2happy) on 2022-11-18 [$2000][ 1356987 ] Medium CVE-2023-0136: Inappropriate implementation in Fullscreen API
Severity: medium
Chrome
Stable Channel Update for Desktop: CVE-2023-0138
vendor_chrome·2023-01-10·CVSS 8.8
CVE-2023-0138 [LOW] Stable Channel Update for Desktop: CVE-2023-0138
Stable Channel Update for Desktop
CVE-2023-0138: Heap buffer overflow in libphonenumber. Reported by Michael Dau on 2022-07-23 [$2000][ 1367632 ] Low CVE-2023-0139: Insufficient validation of untrusted input in Downloads
Reported by Axel Chong on 2022-09-24 [$1000][ 1326788 ] Low CVE-2023-0140: Inappropriate implementation in File System API
Severity: low
Suricata
ET EXPLOIT Citrix ADC and NetScaler Gateway Information Disclosure Attempt (CVE-2023-4966)
suricata·2023-10-29·CVSS 9.4
CVE-2023-4966 [CRITICAL] ET EXPLOIT Citrix ADC and NetScaler Gateway Information Disclosure Attempt (CVE-2023-4966)
ET EXPLOIT Citrix ADC and NetScaler Gateway Information Disclosure Attempt (CVE-2023-4966)
Rule: alert http $EXTERNAL_NET any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Citrix ADC and NetScaler Gateway Information Disclosure Attempt (CVE-2023-4966)"; flow:established,to_server; flowbits:set,ET.CVE-2023-4966.LeakAttempt; http.uri; content:"/oauth/rp/.well-known/openid-configuration"; fast_pattern; http.host; bsize:>2000; reference:url,www.assetnote.io/resources/research/citrix-bleed-leaking-session-tokens-with-cve-2023-4966; reference:cve,2023-4966; classtype:attempted-admin; sid:2048931; rev:2; metadata:affected_product Citrix, attack_target Web_Server, created_at 2023_10_29, cve CVE_2023_4966, deployment Perimeter, deployment SSLDecrypt, performance_impact Low, confidence High, si
No writeups or analysis indexed.
2023-05-02
Published