Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Lack of URL normalization allows rendering previews for disallowed domains
Vulnerability Description
Mattermost fails to normalize UTF confusable characters when determining if a preview should be generated for a hyperlink, allowing an attacker to trigger link preview on a disallowed domain using a specially crafted link.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Vulnerability Type
输入验证不恰当
Vulnerability Title
Mattermost 输入验证错误漏洞
Vulnerability Description
Mattermost是美国Mattermost公司的一个开源协作平台。 Mattermost存在输入验证错误漏洞,该漏洞源于在确定是否应为超链接生成预览时,Mattermost 未能规范化 UTF 易混淆字符,攻击者利用该漏洞可以使用特制链接在不允许的域上触发链接预览。
CVSS Information
N/A
Vulnerability Type
N/A