cbcvebase.
CVE-2023-49607
published 2023-12-12

CVE-2023-49607: Mattermost fails to validate the type of the "reminder" body request parameter allowing an attacker to crash the Playbook Plugin when updating the status…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
Mattermost fails to validate the type of the "reminder" body request parameter allowing an attacker to crash the Playbook Plugin when updating the status dialog.

Affected

7 ranges
VendorProductVersion rangeFixed in
mattermostmattermost<= 8.1.5
mattermostmattermost_server<= 7.8.14
mattermostmattermost_server
mattermostmattermost_server8.0.0 – 8.1.5
mattermostmattermost_server9.0.0 – 9.0.3
mattermostmattermost_server9.1.0 – 9.1.2
mattermostmattermost_server9.2.0 – 9.2.1