3.7
/ 10
LOW
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Description
Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to get channel subscription details without proper access to the channel via API call to the GET autocomplete/GetChannelSubscriptions endpoint.
Basic Information
ID
CVE-2025-53857
Source
Mattermost
Published
Aug 11, 2025 at 18:57
Modified
Aug 11, 2025 at 19:37
Affected Product
Vendor
Mattermost
Product
Mattermost Confluence Plugin
Affected Versions
Mattermost Mattermost Confluence Plugin 0