CVE-2025-13767 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Mattermost versions 11.1.x
Medium CVSS: 4.3

CVE-2025-13767

Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fails to validate user channel membership when attaching Mattermost posts as comments to Jira issues, which allows an authenticated attacker with access to the Jira plugin to read post content and attachments from channels they do not have access to.
Vendor
Mattermost
Product
Mattermost Server
CWE
CWE-863
Yayın Tarihi
2025-12-24 08:15:45
Güncelleme
2025-12-31 18:56:27
Source Identifier
responsibledisclosure@mattermost.com
KEV Date Added
-

Kategoriler

Referanslar