Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
3.7
CVE-2025-49221
- EPSS 0.06%
- Published 11.08.2025 18:56:59
- Last modified 24.09.2025 20:44:19
Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attackers to access subscription details without via API call to GET subscription endpoint.
7.2
CVE-2025-44004
- EPSS 0.04%
- Published 11.08.2025 18:56:58
- Last modified 25.09.2025 18:53:07
Mattermost Confluence Plugin version <1.5.0 fails to check the authorization of the user to the Mattermost instance which allows attackers to create a channel subscription without proper authorization via API call to the create channel subscription e...
- EPSS 0.04%
- Published 11.08.2025 18:56:57
- Last modified 25.09.2025 18:04:50
Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to get channel subscription details without proper access to the channel via API call to the Get Channel Subscriptions details end...