Mattermost

Confluence

13 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 11.08.2025 18:57:07
  • Zuletzt bearbeitet 24.09.2025 00:34:43

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create channel subscription without proper access to the channel via API call to the create channel subscription endpoint.

  • EPSS 0.11%
  • Veröffentlicht 11.08.2025 18:57:06
  • Zuletzt bearbeitet 24.09.2025 00:41:21

Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attackers to edit channel subscriptions via API call to the edit channel subscription endpoint.

  • EPSS 0.15%
  • Veröffentlicht 11.08.2025 18:57:06
  • Zuletzt bearbeitet 24.09.2025 00:37:15

Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to create channel subscription endpoint with an invalid request body.

  • EPSS 0.06%
  • Veröffentlicht 11.08.2025 18:57:05
  • Zuletzt bearbeitet 24.09.2025 00:42:37

Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to server webhook endpoint with an invalid request body.

  • EPSS 0.03%
  • Veröffentlicht 11.08.2025 18:57:04
  • Zuletzt bearbeitet 25.09.2025 19:15:04

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to create a subscription for a Confluence space the user does not have access to via the create subscription endpoint.

  • EPSS 0.04%
  • Veröffentlicht 11.08.2025 18:57:03
  • Zuletzt bearbeitet 25.09.2025 18:56:23

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create a channel subscription without proper access to the channel via API call to the edit channel subscription endpoint.

  • EPSS 0.04%
  • Veröffentlicht 11.08.2025 18:57:02
  • Zuletzt bearbeitet 25.09.2025 18:55:50

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to get channel subscription details without proper access to the channel via API call to the GET autocomplete/GetChannelSubscripti...

  • EPSS 0.06%
  • Veröffentlicht 11.08.2025 18:57:01
  • Zuletzt bearbeitet 25.09.2025 18:55:36

Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to server webhook endpoint with an invalid request body.

  • EPSS 0.06%
  • Veröffentlicht 11.08.2025 18:57:00
  • Zuletzt bearbeitet 25.09.2025 18:06:35

Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to update channel subscription endpoint with an invalid request body.

  • EPSS 0.03%
  • Veröffentlicht 11.08.2025 18:56:59
  • Zuletzt bearbeitet 25.09.2025 18:55:22

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to edit a subscription for a Confluence space the user does not have access for via edit subscription endpoint.