cbcvebase.
CVE-2025-13767
published 2025-12-24

CVE-2025-13767: Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fails to validate user channel membership when attaching…

medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fails to validate user channel membership when attaching Mattermost posts as comments to Jira issues, which allows an authenticated attacker with access to the Jira plugin to read post content and attachments from channels they do not have access to.

Affected

17 ranges
VendorProductVersion rangeFixed in
github.commattermost_mattermost-server>= 10.11.0 < 10.11.810.11.8
github.commattermost_mattermost-server>= 10.11.0+incompatible < 10.11.8+incompatible10.11.8+incompatible
github.commattermost_mattermost-server>= 10.12.0 < 10.12.410.12.4
github.commattermost_mattermost-server>= 10.12.0+incompatible < 10.12.4+incompatible10.12.4+incompatible
github.commattermost_mattermost-server>= 11.0.0 < 11.0.611.0.6
github.commattermost_mattermost-server>= 11.0.1+incompatible < 11.0.6+incompatible11.0.6+incompatible
github.commattermost_mattermost-server>= 11.1.0 < 11.1.111.1.1
github.commattermost_mattermost-server>= 11.1.0+incompatible < 11.1.1+incompatible11.1.1+incompatible
github.commattermost_mattermost_server_v8>= 0 < 8.0.0-20251121122154-b57c297c6d78.0.0-20251121122154-b57c297c6d7
mattermostmattermost10.11.0 – 10.11.7
mattermostmattermost10.12.0 – 10.12.3
mattermostmattermost11.0.0 – 11.0.5
mattermostmattermost11.1.0 – 11.1.0
mattermostmattermost_server>= 10.11.0 < 10.11.810.11.8
mattermostmattermost_server>= 10.12.0 < 10.12.410.12.4
mattermostmattermost_server>= 11.0.0 < 11.0.611.0.6
mattermostmattermost_server>= 11.1.0 < 11.1.111.1.1