Security Advisory

CVE-2025-13767

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-12-24 08:01:27
Last updated 2025-12-24 16:36:22
Assigner Mattermost
State PUBLISHED

Description

Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fails to validate user channel membership when attaching Mattermost posts as comments to Jira issues, which allows an authenticated attacker with access to the Jira plugin to read post content and attachments from channels they do not have access to.