4
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
Description
Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create channel subscription without proper access to the channel via API call to the create channel subscription endpoint.
Basic Information
ID
CVE-2025-8285
Source
Mattermost
Published
Aug 11, 2025 at 18:57
Modified
Aug 11, 2025 at 19:41
Affected Product
Vendor
Mattermost
Product
Mattermost Confluence Plugin
Affected Versions
Mattermost Mattermost Confluence Plugin 0