Total vulnerabilities in the database
Mattermost is grouping calls in the /metrics endpoint by id and reports that id in the response. Since this id is the channelID, the public /metrics endpoint is revealing channelIDs.
Software | From | Fixed in |
---|---|---|
![]() |
- | 7.8.14 |
![]() |
- | 8.1.5 |
mattermost / mattermost_server | 8.0.0 | 8.1.5 |
mattermost / mattermost_server | - | 7.8.14 |