Mattermost Confluence Plugin is Missing Authentication for Critical Function
High severity
GitHub Reviewed
Published
Aug 11, 2025
to the GitHub Advisory Database
•
Updated Aug 11, 2025
Package
Affected versions
< 1.5.0
Patched versions
1.5.0
Description
Published by the National Vulnerability Database
Aug 11, 2025
Published to the GitHub Advisory Database
Aug 11, 2025
Reviewed
Aug 11, 2025
Last updated
Aug 11, 2025
Mattermost Confluence Plugin version <1.5.0 fails to check the authorization of the user to the Mattermost instance which allows attackers to create a channel subscription without proper authorization via API call to the create channel subscription endpoint.
References