Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vc9q-cghx-53cj

Опубликовано: 29 мая 2023
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

Mattermost fails to normalize UTF confusable characters when determining if a preview should be generated for a hyperlink, allowing an attacker to trigger link preview on a disallowed domain using a specially crafted link.

Mattermost fails to normalize UTF confusable characters when determining if a preview should be generated for a hyperlink, allowing an attacker to trigger link preview on a disallowed domain using a specially crafted link.

EPSS

Процентиль: 39%
0.0017
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 4.3
nvd
около 2 лет назад

Mattermost fails to normalize UTF confusable characters when determining if a preview should be generated for a hyperlink, allowing an attacker to trigger link preview on a disallowed domain using a specially crafted link.

CVSS3: 4.3
debian
около 2 лет назад

Mattermost fails to normalize UTF confusable characters when determini ...

EPSS

Процентиль: 39%
0.0017
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-20