Mattermost Confluence Plugin Channel Subscription Access Vulnerability
Vulnerability
A vulnerability exists in the Mattermost Confluence Plugin versions prior to 1.5.0, where the plugin fails to properly verify user access to channels. This oversight allows attackers to retrieve channel subscription details via an API call to the Get Channel Subscriptions details endpoint, without having the appropriate access to the channel.
Impact
Exploitation of this vulnerability could lead to unauthorized access to channel subscription details, potentially allowing attackers to gather information about user interactions and engagements within the channel.
Remediation
Users can upgrade to Mattermost Confluence Plugin version 1.5.0 or later to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
