CVE 7.2 HIGH

Unauthenticated Channel Subscription Edit in Mattermost Confluence Plugin_CVE-2025-54478

7.2 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

Description

Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attackers to edit channel subscriptions via API call to the edit channel subscription endpoint.

Basic Information

ID CVE-2025-54478
Source Mattermost
Published Aug 11, 2025 at 18:57
Modified Aug 11, 2025 at 19:40

Affected Product

Vendor Mattermost
Product Mattermost Confluence Plugin
Affected Versions Mattermost Mattermost Confluence Plugin 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.