ZeroHour

CVE-2025-54525

CVSS 3.1
7.5 high
EPSS
<1%p26
Published
()
Modified
Description

Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to create channel subscription endpoint with an invalid request body.

Vendors
mattermost
Products
confluence
Weakness
CWE-1287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.