CVE-2025-13767
Unknown Unknown - Not Provided
Improper Access Control in Mattermost Jira Plugin Allows Data Exposure

Publication date: 2025-12-24

Last updated on: 2025-12-24

Assigner: Mattermost, Inc.

Description
Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fails to validate user channel membership when attaching Mattermost posts as comments to Jira issues, which allows an authenticated attacker with access to the Jira plugin to read post content and attachments from channels they do not have access to.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-12-24
Last Modified
2025-12-24
Generated
2026-05-07
AI Q&A
2025-12-24
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 4 associated CPEs
Vendor Product Version / Range
mattermost mattermost 11.1.0
mattermost mattermost 10.11.7
mattermost mattermost 11.0.5
mattermost mattermost 10.12.3
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability occurs in certain versions of Mattermost where the system fails to properly check if a user is a member of a channel before allowing them to attach Mattermost posts as comments to Jira issues. As a result, an authenticated attacker who has access to the Jira plugin can read the content and attachments of posts from channels they are not authorized to access.


How can this vulnerability impact me? :

The vulnerability can lead to unauthorized disclosure of sensitive information because an attacker with Jira plugin access can read posts and attachments from restricted Mattermost channels. This could compromise confidentiality of communications and data shared within those channels.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart