Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9pj7-jh2r-87g8

Опубликовано: 13 фев. 2026
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Mattermost doesn't validate user permissions when creating Jira issues from Mattermost posts

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to validate user permissions when creating Jira issues from Mattermost posts, which allows an authenticated attacker with access to the Jira plugin to read post content and attachments from channels they do not have access to via the /create-issue API endpoint by providing the post ID of an inaccessible post.. Mattermost Advisory ID: MMSA-2025-00550

Пакеты

Наименование

github.com/mattermost/mattermost-server

go
Затронутые версииВерсия исправления

>= 11.2.0, <= 11.2.1

11.2.2

Наименование

github.com/mattermost/mattermost-server

go
Затронутые версииВерсия исправления

>= 11.1.0, <= 11.1.2

11.1.3

Наименование

github.com/mattermost/mattermost-server

go
Затронутые версииВерсия исправления

>= 10.11.0, <= 10.11.9

10.11.10

EPSS

Процентиль: 1%
0.00009
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 4.3
nvd
около 2 месяцев назад

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to validate user permissions when creating Jira issues from Mattermost posts, which allows an authenticated attacker with access to the Jira plugin to read post content and attachments from channels they do not have access to via the /create-issue API endpoint by providing the post ID of an inaccessible post.. Mattermost Advisory ID: MMSA-2025-00550

CVSS3: 4.3
debian
около 2 месяцев назад

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11 ...

EPSS

Процентиль: 1%
0.00009
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-863