CVE-2023-6459: Mattermost Server

Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.

Mattermost is grouping calls in the /metrics endpoint by id and reports that id in the response. Since this id is the channelID, the public /metrics endpoint is revealing channelIDs.

Affected products

  • Mattermost Mattermost Server: before 7.8.14 (fixed in 7.8.14); from 8.0.0, before 8.1.5 (fixed in 8.1.5)

Published 2023-12-06. Last modified 2026-06-17.