PT-2025-32579 · Mattermost · Mattermost Confluence Plugin

Lorenzo Gallegos

·

Publicado

2025-07-10

·

Atualizado

2025-08-20

·

CVE-2025-53910

CVSS v3.1

4.0

Média

VetorAV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Mattermost Confluence Plugin versions prior to 1.5.0
Description: The Mattermost Confluence Plugin does not verify user access to a channel, enabling attackers to create channel subscriptions without authorization through an API call to the edit channel subscription endpoint /api/v1/channels/{channel id}/subscriptions/{user id}. The vulnerable parameter is user id.
Recommendations: Update Mattermost Confluence Plugin to version 1.5.0 or later.

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-09759
CVE-2025-53910
GHSA-V6C8-G53H-MC2H
GO-2025-3869
OPENSUSE-SU-2025:15469-1

Produtos afetados

Mattermost Confluence Plugin