NA

CVE-2023-6459

Published: 06/12/2023 Updated: 12/12/2023
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Mattermost is grouping calls in the /metrics endpoint by id and reports that id in the response. Since this id is the channelID, the public /metrics endpoint is revealing channelIDs.

Vulnerable Product Search on Vulmon Subscribe to Product

mattermost mattermost server