Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-6459


Mattermost is grouping calls in the /metrics endpoint by id and reports that id in the response. Since this id is the channelID, the public /metrics endpoint is revealing channelIDs.


Published

2023-12-06T09:15:09.140

Last Modified

2024-11-21T08:43:54.087

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-200
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mattermost mattermost_server < 7.8.14 Yes
Application mattermost mattermost_server < 8.1.5 Yes

References