3.7
/ 10
LOW
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Description
Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attackers to access subscription details without via API call to GET subscription endpoint.
Basic Information
ID
CVE-2025-49221
Source
Mattermost
Published
Aug 11, 2025 at 18:56
Modified
Aug 11, 2025 at 19:35
Affected Product
Vendor
Mattermost
Product
Mattermost Confluence Plugin
Affected Versions
Mattermost Mattermost Confluence Plugin 0