Mattermost fails to normalize UTF confusable characters when determining if a preview should be generated for a hyperlink, allowing an attacker to trigger link preview on a disallowed domain using a specially crafted link.
{ "versions": [ { "introduced": "5.34.0" }, { "fixed": "7.1.9" }, { "introduced": "7.2.0" }, { "fixed": "7.8.4" }, { "introduced": "7.9.0" }, { "fixed": "7.9.3" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-2808.json"