CVE-2025-49221: Mattermost Confluence Plugin has Missing Authorization vulnerability
Mattermost Confluence Plugin versions < 1.5.0 fail to enforce authentication of the user to the Mattermost instance, which allows unauthenticated attackers to access subscription details via an API call to the GET subscription endpoint.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-49221 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →