Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-24181 | Mattermost Confluence Plugin has Missing Authorization vulnerability |
Github GHSA |
GHSA-vpcr-fqpc-386h | Mattermost Confluence Plugin has Missing Authorization vulnerability |
Solution
Update Mattermost Confluence Plugin to version 1.5.0 or higher.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
Thu, 25 Sep 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost confluence
|
|
| CPEs | cpe:2.3:a:mattermost:confluence:*:*:*:*:*:mattermost:*:* | |
| Vendors & Products |
Mattermost confluence
|
Tue, 12 Aug 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost
Mattermost mattermost |
|
| Vendors & Products |
Mattermost
Mattermost mattermost |
Mon, 11 Aug 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 11 Aug 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to get channel subscription details without proper access to the channel via API call to the Get Channel Subscriptions details endpoint. | |
| Title | Unauthorized Channel Subscription Read in Mattermost Confluence Plugin | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2025-08-11T19:34:12.187Z
Reserved: 2025-07-28T14:26:12.469Z
Link: CVE-2025-44001
Updated: 2025-08-11T19:34:06.693Z
Status : Analyzed
Published: 2025-08-11T19:15:27.467
Modified: 2025-09-25T18:04:50.753
Link: CVE-2025-44001
No data.
OpenCVE Enrichment
Updated: 2025-08-12T11:46:55Z
EUVD
Github GHSA