VDB
Sign up
MEDIUM5.3

GHSA-63cv-4pc2-4fcf

Mattermost Exposure of Sensitive Information to an Unauthorized Actor vulnerability

Quick fix

GHSA-63cv-4pc2-4fcf — github.com/mattermost/mattermost-server/v6: upgrade to the fixed version with the command below.

go get github.com/mattermost/mattermost-server/v6@v7.8.14

Details

Mattermost is grouping calls in the /metrics endpoint by id and reports that id in the response. Since this id is the channelID, the public /metrics endpoint is revealing channelIDs.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/mattermost/mattermost-server/v6
Introduced in: 0Fixed in: 7.8.14
Fixgo get github.com/mattermost/mattermost-server/v6@v7.8.14
Go/github.com/mattermost/mattermost/server/v8
Introduced in: 0Fixed in: 8.1.5
Fixgo get github.com/mattermost/mattermost/server/v8@v8.1.5

References