Описание
Mattermost Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Mattermost is grouping calls in the /metrics endpoint by id and reports that id in the response. Since this id is the channelID, the public /metrics endpoint is revealing channelIDs.
Пакеты
Наименование
github.com/mattermost/mattermost-server/v6
go
Затронутые версииВерсия исправления
< 7.8.14
7.8.14
Наименование
github.com/mattermost/mattermost/server/v8
go
Затронутые версииВерсия исправления
< 8.1.5
8.1.5
Связанные уязвимости
CVSS3: 5.3
nvd
около 2 лет назад
Mattermost is grouping calls in the /metrics endpoint by id and reports that id in the response. Since this id is the channelID, the public /metrics endpoint is revealing channelIDs.
CVSS3: 5.3
debian
около 2 лет назад
Mattermost is grouping calls inthe /metrics endpoint by id and reports ...