CVE-2025-13767
MEDIUM4.3EPSS 0.03%Mattermost doesn't validate user channel membership when attaching Mattermost posts as comments to Jira issues
發布日:2025/12/24修改日:2026/2/27
描述
Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fails to validate user channel membership when attaching Mattermost posts as comments to Jira issues, which allows an authenticated attacker with access to the Jira plugin to read post content and attachments from channels they do not have access to.
受影響套件(6)
- Go/github.com/mattermost/mattermost-server>= 10.11.0, < 10.11.8
- Go/github.com/mattermost/mattermost-server>= 10.11.0+incompatible, < 10.11.8+incompatible, >= 10.12.0+incompatible, < 10.12.4+incompatible, >= 11.0.1+incompatible, < 11.0.6+incompatible, >= 11.1.0+incompatible, < 11.1.1+incompatible
- Go/github.com/mattermost/mattermost-server/v5from 0
- Go/github.com/mattermost/mattermost-server/v6from 0
- Go/github.com/mattermost/mattermost/server/v8from 0, < 8.0.0-20251121122154-b57c297c6d7
- Go/github.com/mattermost/mattermost/server/v8from 0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.3 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
參考連結(7)
- ADVISORYhttps://github.com/advisories/GHSA-fmqf-pmcm-8cx9
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2025-13767
- PATCHhttps://github.com/mattermost/mattermost
- WEBhttps://github.com/mattermost/mattermost/commit/b57c297c6d7ae6812d85e32a625806ac9555deee
- WEBhttps://github.com/mattermost/mattermost/pull/34551
- WEBhttps://mattermost.com/security-updates
- WEBhttps://pkg.go.dev/vuln/GO-2026-4259