CVE-2025-49221
published 2025-08-11CVE-2025-49221: Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attackers to…
PriorityP421low3.7CVSS 3.1
AVNACHPRNUINSUCLINAN
EPSS
0.25%
15.9th percentile
Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attackers to access subscription details without via API call to GET subscription endpoint.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | mattermost_mattermost-plugin-confluence | >= 0 < 1.5.0 | 1.5.0 |
| mattermost | confluence | < 1.5.0 | 1.5.0 |
| mattermost | mattermost_confluence_plugin | < 1.5.0 | 1.5.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Mattermost Confluence Plugin has Missing Authorization vulnerability in github.com/mattermost/mattermost-plugin-confluence
osv·2025-08-18
CVE-2025-49221 Mattermost Confluence Plugin has Missing Authorization vulnerability in github.com/mattermost/mattermost-plugin-confluence
Mattermost Confluence Plugin has Missing Authorization vulnerability in github.com/mattermost/mattermost-plugin-confluence
Mattermost Confluence Plugin has Missing Authorization vulnerability in github.com/mattermost/mattermost-plugin-confluence
OSV
Mattermost Confluence Plugin has Missing Authorization vulnerability
osv·2025-08-11
CVE-2025-49221 [LOW] Mattermost Confluence Plugin has Missing Authorization vulnerability
Mattermost Confluence Plugin has Missing Authorization vulnerability
Mattermost Confluence Plugin versions < 1.5.0 fail to enforce authentication of the user to the Mattermost instance, which allows unauthenticated attackers to access subscription details via an API call to the GET subscription endpoint.
GHSA
Mattermost Confluence Plugin has Missing Authorization vulnerability
ghsa·2025-08-11
CVE-2025-49221 [LOW] CWE-862 Mattermost Confluence Plugin has Missing Authorization vulnerability
Mattermost Confluence Plugin has Missing Authorization vulnerability
Mattermost Confluence Plugin versions < 1.5.0 fail to enforce authentication of the user to the Mattermost instance, which allows unauthenticated attackers to access subscription details via an API call to the GET subscription endpoint.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-08-11
Published