Mattermost is grouping calls in the /metrics endpoint by id and reports that id in the response. Since this id is the channelID, the public /metrics endpoint is revealing channelIDs.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-3122 Mattermost is grouping calls in the /metrics endpoint by id and reports that id in the response. Since this id is the channelID, the public /metrics endpoint is revealing channelIDs.
Github GHSA Github GHSA GHSA-63cv-4pc2-4fcf Mattermost Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Fixes

Solution

Update Mattermost Server to versions 8.1.5, 7.8.14 or higher.


Workaround

No workaround given by the vendor.

References
History

Mon, 02 Dec 2024 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2024-12-16T16:02:20.087Z

Reserved: 2023-12-01T10:14:04.973Z

Link: CVE-2023-6459

cve-icon Vulnrichment

Updated: 2024-08-02T08:28:21.828Z

cve-icon NVD

Status : Modified

Published: 2023-12-06T09:15:09.140

Modified: 2024-11-21T08:43:54.087

Link: CVE-2023-6459

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.