First published: Wed Dec 06 2023(Updated: )
Mattermost is grouping calls in the /metrics endpoint by id and reports that id in the response. Since this id is the channelID, the public /metrics endpoint is revealing channelIDs.
Credit: responsibledisclosure@mattermost.com responsibledisclosure@mattermost.com
Affected Software | Affected Version | How to fix |
---|---|---|
go/github.com/mattermost/mattermost/server/v8 | <8.1.5 | 8.1.5 |
go/github.com/mattermost/mattermost-server/v6 | <7.8.14 | 7.8.14 |
Mattermost Mattermost Server | <7.8.14 | |
Mattermost Mattermost Server | >=8.0.0<8.1.5 |
Update Mattermost Server to versions 8.1.5, 7.8.14 or higher.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-6459 is a vulnerability in Mattermost that allows the public /metrics endpoint to reveal channelIDs.
CVE-2023-6459 has a severity rating of medium with a CVSS score of 5.3.
Mattermost versions up to and including 8.1.5 and 7.8.14 are affected by CVE-2023-6459.
To fix CVE-2023-6459, you should update Mattermost to a version that includes the necessary fixes.
You can find more information about CVE-2023-6459 in the Mattermost security updates, NVD NIST, and GitHub security advisories.