Back to Database
Status published
Medium
CVE-2023-38494
The cloud version of the MeterSphere interface leaks some sensitive data without authentication
Vulnerability Description
MeterSphere is an open-source continuous testing platform. Prior to version 2.10.4 LTS, some interfaces of the Cloud version of MeterSphere do not have configuration permissions, and are sensitively leaked by attackers. Version 2.10.4 LTS contains a patch for this issue.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-38494
Credits & Attribution
No credits recorded in the NVD database.
References
More from metersphere
View All →CVE-2025-62604
MeterSphere logic flaw allows retrieval of arbitrary user information
Medium
5.3
CVE-2025-53639
Metersphere has SQL Injection Vulnerability in Sorting Field
Medium
5.1
CVE-2024-37161
MeterSphere front-end editor stores XSS vulnerability
Medium
4
CVE-2024-36118
Unauthorized viewing of workspace test cases in MeterSphere
Low
3.5
CVE-2024-32467
Meteraphsere vulnerable to unauthorized viewing by workspace members
Medium
5.7
Affected Vendor
metersphere
View all reports →Affected Software
metersphere
Vulnerable Versions:
< 2.10.4-LTS
Timeline
Official Publish:
August 4th, 2023
Last Modified:
October 8th, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:H