Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attackers to edit channel subscriptions via API call to the edit channel subscription endpoint.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
Wed, 24 Sep 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost confluence
|
|
| CPEs | cpe:2.3:a:mattermost:confluence:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mattermost confluence
|
Tue, 12 Aug 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost
Mattermost mattermost |
|
| Vendors & Products |
Mattermost
Mattermost mattermost |
Mon, 11 Aug 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 11 Aug 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attackers to edit channel subscriptions via API call to the edit channel subscription endpoint. | |
| Title | Unauthenticated Channel Subscription Edit in Mattermost Confluence Plugin | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Mattermost
Published: 2025-08-11T18:57:06.088Z
Updated: 2025-08-11T19:40:33.338Z
Reserved: 2025-07-28T14:26:12.443Z
Link: CVE-2025-54478
Updated: 2025-08-11T19:40:27.615Z
Status : Analyzed
Published: 2025-08-11T19:15:30.220
Modified: 2025-09-24T00:41:21.053
Link: CVE-2025-54478
No data.
ReportizFlow