CVE-2023-38494: Metersphere

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

MeterSphere is an open-source continuous testing platform. Prior to version 2.10.4 LTS, some interfaces of the Cloud version of MeterSphere do not have configuration permissions, and are sensitively leaked by attackers. Version 2.10.4 LTS contains a patch for this issue.

Affected products

  • Metersphere Metersphere: before 2.10.4 (fixed in 2.10.4)

Published 2023-08-04. Last modified 2026-06-17.