CVE-2025-54458
BaseFortify
Publication date: 2025-08-11
Last updated on: 2025-09-25
Assigner: Mattermost, Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| mattermost | confluence | to 1.5.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-862 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in Mattermost Confluence Plugin versions before 1.5.0 allows attackers to create a subscription for a Confluence space without having access to that space. The plugin fails to verify whether the user has permission to access the Confluence space when creating a subscription via the create subscription endpoint.
How can this vulnerability impact me? :
An attacker could exploit this vulnerability to subscribe to Confluence spaces they should not have access to, potentially gaining unauthorized visibility or notifications related to those spaces. This could lead to information disclosure or unauthorized monitoring of restricted content.