Skip to main content

Improper Check for Unusual or Exceptional Conditions

CVE-2025-52931

Severity High
Score 7.5/10

Summary

Mattermost Confluence Plugin versions prior to 1.5.0-rc1 fail to handle unexpected request bodies, which allows attackers to crash the plugin via constant hits to update channel subscription endpoint with an invalid request body. This has the same fix as CVE-2025-53910.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • NONE
  • HIGH

CWE-754 - Improper Check for Unusual or Exceptional Conditions

The software does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the software.

Advisory Timeline

  • Published