Mattermost Confluence Plugin Access Control Vulnerability in Subscription Creation
Vulnerability
A vulnerability exists in the Mattermost Confluence Plugin versions prior to 1.5.0, where the plugin fails to properly verify user access to Confluence spaces. This oversight allows attackers to create subscriptions for spaces they do not have access to, by exploiting the create subscription endpoint.
Impact
Exploitation of this vulnerability could lead to unauthorized subscription creation for Confluence spaces, allowing users to receive updates or notifications about those spaces without having the appropriate access.
Remediation
Users can upgrade to Mattermost Confluence Plugin version 1.5.0 or later to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
