CVE-2023-6459: Public endpoint /metrics of Calls plugin reveals channel IDs
Published Dec 6, 2023
·Updated
Mattermost is grouping calls in the /metrics endpoint by id and reports that id in the response. Since this id is the channelID, the public /metrics endpoint is revealing channelIDs.
Affected Software
4 affected componentsFixes available
go/github.com/mattermost/mattermost/server/v8<8.1.5
8.1.5
go/github.com/mattermost/mattermost-server/v6<7.8.14
7.8.14
Mattermost Mattermost Server<7.8.14
Mattermost Mattermost Server>=8.0.0<8.1.5
Remediation
Information
Update Mattermost Server to versions 8.1.5, 7.8.14 or higher.
Event History
Dec 6, 2023
CVE Published
08:11 AM
Data Sourced
08:11 AM
RemedyDescriptionSeverityWeakness
Advisory Published
09:30 AM
Frequently Asked Questions
1
What is CVE-2023-6459?
CVE-2023-6459 is a vulnerability in Mattermost that allows the public /metrics endpoint to reveal channelIDs.
2
How severe is CVE-2023-6459?
CVE-2023-6459 has a severity rating of medium with a CVSS score of 5.3.
3
Which version of Mattermost is affected by CVE-2023-6459?
Mattermost versions up to and including 8.1.5 and 7.8.14 are affected by CVE-2023-6459.
4
How can I fix CVE-2023-6459?
To fix CVE-2023-6459, you should update Mattermost to a version that includes the necessary fixes.
5
Where can I find more information about CVE-2023-6459?
You can find more information about CVE-2023-6459 in the Mattermost security updates, NVD NIST, and GitHub security advisories.