CVE-2023-5967: Mattermost
Medium severity, CVSS 4.3. EPSS: 0.5% chance of exploitation in the next 30 days.
Mattermost fails to properly validate requests to the Calls plugin, allowing an attacker sending a request without a User Agent header to cause a panic and crash the Calls plugin
Affected products
- Mattermost Mattermost: up to and including 7.8.11; from 8.0.0, up to and including 8.0.3; from 8.1.0, up to and including 8.1.2
Published 2023-11-06. Last modified 2026-06-17.