Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to get channel subscription details without proper access to the channel via API call to the Get Channel Subscriptions details endpoint.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://mattermost.com/security-updates |
![]() ![]() |
History
Tue, 12 Aug 2025 12:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Mattermost
Mattermost mattermost |
|
Vendors & Products |
Mattermost
Mattermost mattermost |
Mon, 11 Aug 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 11 Aug 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to get channel subscription details without proper access to the channel via API call to the Get Channel Subscriptions details endpoint. | |
Title | Unauthorized Channel Subscription Read in Mattermost Confluence Plugin | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Mattermost
Published: 2025-08-11T18:56:57.280Z
Updated: 2025-08-11T19:34:12.187Z
Reserved: 2025-07-28T14:26:12.469Z
Link: CVE-2025-44001

Updated: 2025-08-11T19:34:06.693Z

Status : Received
Published: 2025-08-11T19:15:27.467
Modified: 2025-08-11T19:15:27.467
Link: CVE-2025-44001

No data.