CVE 4 MEDIUM

Unauthorized Channel Subscription Read in Mattermost Confluence Plugin_CVE-2025-44001

4 / 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N

Description

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to get channel subscription details without proper access to the channel via API call to the Get Channel Subscriptions details endpoint.

Basic Information

ID CVE-2025-44001
Source Mattermost
Published Aug 11, 2025 at 18:56
Modified Aug 11, 2025 at 19:34

Affected Product

Vendor Mattermost
Product Mattermost Confluence Plugin
Affected Versions Mattermost Mattermost Confluence Plugin 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.