{"id":"GHSA-cmpr-8prq-w5p5","summary":"Mattermost Confluence Plugin has Missing Authorization vulnerability","details":"Mattermost Confluence Plugin versions \u003c 1.5.0 fail to check user access to Confluence spaces, which allows attackers to edit subscriptions for Confluence spaces that users do not have access to through the edit subscription endpoint.","aliases":["CVE-2025-48731","GO-2025-3861"],"modified":"2025-08-18T13:59:16.543320Z","published":"2025-08-11T21:31:39Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2025-08-11T22:59:08Z","nvd_published_at":"2025-08-11T19:15:27Z","cwe_ids":["CWE-862"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-48731"},{"type":"PACKAGE","url":"https://github.com/mattermost/mattermost-plugin-confluence"},{"type":"WEB","url":"https://mattermost.com/security-updates"}],"affected":[{"package":{"name":"github.com/mattermost/mattermost-plugin-confluence","ecosystem":"Go","purl":"pkg:golang/github.com/mattermost/mattermost-plugin-confluence"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.5.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-cmpr-8prq-w5p5/GHSA-cmpr-8prq-w5p5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"}]}