GHSA-42M6-5VM7-FJV2 Mattermost Confluence Plugin has Missing Authorization vulnerability
Discription

Mattermost Confluence Plugin versions < 1.5.0 fail to check user access to the channel, allowing attackers to get channel subscription details without proper access to the channel via API call to the GET autocomplete/GetChannelSubscriptions…Read More
References
Back to Main