7.5
CVE-2025-54525
- EPSS 0.15%
- Veröffentlicht 11.08.2025 18:57:06
- Zuletzt bearbeitet 24.09.2025 00:37:15
- Quelle responsibledisclosure@mattermo
- Teams Watchlist Login
- Unerledigt Login
Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to create channel subscription endpoint with an invalid request body.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mattermost ≫ Confluence Version < 1.5.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.15% | 0.36 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
responsibledisclosure@mattermost.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-1287 Improper Validation of Specified Type of Input
The product receives input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type.