CVE 3.7 LOW

Lack of Authorization on Get Channel Subscriptions for Autocomplete in Mattermost Confluence Plugin_CVE-2025-53857

3.7 / 10
LOW
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Description

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to get channel subscription details without proper access to the channel via API call to the GET autocomplete/GetChannelSubscriptions endpoint.

Basic Information

ID CVE-2025-53857
Source Mattermost
Published Aug 11, 2025 at 18:57
Modified Aug 11, 2025 at 19:37

Affected Product

Vendor Mattermost
Product Mattermost Confluence Plugin
Affected Versions Mattermost Mattermost Confluence Plugin 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.