Skip to content

Commit 8c14ff7

Browse files
1 parent 7ba24dc commit 8c14ff7

File tree

2 files changed

+145
-36
lines changed

2 files changed

+145
-36
lines changed
Lines changed: 145 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,145 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-fmqf-pmcm-8cx9",
4+
"modified": "2025-12-26T18:40:17Z",
5+
"published": "2025-12-24T09:30:22Z",
6+
"aliases": [
7+
"CVE-2025-13767"
8+
],
9+
"summary": "Mattermost doesn't validate user channel membership when attaching Mattermost posts as comments to Jira issues",
10+
"details": "Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fails to validate user channel membership when attaching Mattermost posts as comments to Jira issues, which allows an authenticated attacker with access to the Jira plugin to read post content and attachments from channels they do not have access to.",
11+
"severity": [
12+
{
13+
"type": "CVSS_V3",
14+
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
15+
}
16+
],
17+
"affected": [
18+
{
19+
"package": {
20+
"ecosystem": "Go",
21+
"name": "github.com/mattermost/mattermost/server/v8"
22+
},
23+
"ranges": [
24+
{
25+
"type": "ECOSYSTEM",
26+
"events": [
27+
{
28+
"introduced": "0"
29+
},
30+
{
31+
"fixed": "8.0.0-20251121122154-b57c297c6d7"
32+
}
33+
]
34+
}
35+
]
36+
},
37+
{
38+
"package": {
39+
"ecosystem": "Go",
40+
"name": "github.com/mattermost/mattermost-server"
41+
},
42+
"ranges": [
43+
{
44+
"type": "ECOSYSTEM",
45+
"events": [
46+
{
47+
"introduced": "10.11.0"
48+
},
49+
{
50+
"fixed": "10.11.8"
51+
}
52+
]
53+
}
54+
]
55+
},
56+
{
57+
"package": {
58+
"ecosystem": "Go",
59+
"name": "github.com/mattermost/mattermost-server"
60+
},
61+
"ranges": [
62+
{
63+
"type": "ECOSYSTEM",
64+
"events": [
65+
{
66+
"introduced": "10.12.0"
67+
},
68+
{
69+
"fixed": "10.12.4"
70+
}
71+
]
72+
}
73+
]
74+
},
75+
{
76+
"package": {
77+
"ecosystem": "Go",
78+
"name": "github.com/mattermost/mattermost-server"
79+
},
80+
"ranges": [
81+
{
82+
"type": "ECOSYSTEM",
83+
"events": [
84+
{
85+
"introduced": "11.0.0"
86+
},
87+
{
88+
"fixed": "11.0.6"
89+
}
90+
]
91+
}
92+
]
93+
},
94+
{
95+
"package": {
96+
"ecosystem": "Go",
97+
"name": "github.com/mattermost/mattermost-server"
98+
},
99+
"ranges": [
100+
{
101+
"type": "ECOSYSTEM",
102+
"events": [
103+
{
104+
"introduced": "11.1.0"
105+
},
106+
{
107+
"fixed": "11.1.1"
108+
}
109+
]
110+
}
111+
]
112+
}
113+
],
114+
"references": [
115+
{
116+
"type": "ADVISORY",
117+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-13767"
118+
},
119+
{
120+
"type": "WEB",
121+
"url": "https://github.com/mattermost/mattermost/pull/34551"
122+
},
123+
{
124+
"type": "WEB",
125+
"url": "https://github.com/mattermost/mattermost/commit/b57c297c6d7ae6812d85e32a625806ac9555deee"
126+
},
127+
{
128+
"type": "PACKAGE",
129+
"url": "https://github.com/mattermost/mattermost"
130+
},
131+
{
132+
"type": "WEB",
133+
"url": "https://mattermost.com/security-updates"
134+
}
135+
],
136+
"database_specific": {
137+
"cwe_ids": [
138+
"CWE-863"
139+
],
140+
"severity": "MODERATE",
141+
"github_reviewed": true,
142+
"github_reviewed_at": "2025-12-26T18:40:17Z",
143+
"nvd_published_at": "2025-12-24T08:15:45Z"
144+
}
145+
}

advisories/unreviewed/2025/12/GHSA-fmqf-pmcm-8cx9/GHSA-fmqf-pmcm-8cx9.json

Lines changed: 0 additions & 36 deletions
This file was deleted.

0 commit comments

Comments
 (0)