cbcvebase.
CVE-2023-6459
published 2023-12-06

CVE-2023-6459: Mattermost is grouping calls in the /metrics endpoint by id and reports that id in the response. Since this id is the channelID, the public /metrics endpoint…

medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
Mattermost is grouping calls in the /metrics endpoint by id and reports that id in the response. Since this id is the channelID, the public /metrics endpoint is revealing channelIDs.

Affected

5 ranges
VendorProductVersion rangeFixed in
github.commattermost_mattermost-server_v6>= 0 < 7.8.147.8.14
github.commattermost_mattermost_server_v8>= 0 < 8.1.58.1.5
mattermostmattermost<= 7.8.13
mattermostmattermost_server< 7.8.147.8.14
mattermostmattermost_server>= 8.0.0 < 8.1.58.1.5