CVE-2025-13767
Unknown
Unknown - Not Provided
Improper Access Control in Mattermost Jira Plugin Allows Data Exposure
Publication date: 2025-12-24
Last updated on: 2025-12-24
Assigner: Mattermost, Inc.
Description
Description
Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fails to validate user channel membership when attaching Mattermost posts as comments to Jira issues, which allows an authenticated attacker with access to the Jira plugin to read post content and attachments from channels they do not have access to.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| mattermost | mattermost | 11.1.0 |
| mattermost | mattermost | 10.11.7 |
| mattermost | mattermost | 11.0.5 |
| mattermost | mattermost | 10.12.3 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-863 | The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. |