Home
MEDIUM: 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NDefault status
unaffected
11.1.0 (semver)
affected
11.0.0 (semver)
affected
10.12.0 (semver)
affected
10.11.0 (semver)
affected
11.2.0
unaffected
11.1.1
unaffected
11.0.6
unaffected
10.12.4
unaffected
10.11.8
unaffected
Description
Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fails to validate user channel membership when attaching Mattermost posts as comments to Jira issues, which allows an authenticated attacker with access to the Jira plugin to read post content and attachments from channels they do not have access to.
Problem types
CWE-863: Incorrect Authorization
Product status
11.1.0 (semver)
11.0.0 (semver)
10.12.0 (semver)
10.11.0 (semver)
11.2.0
11.1.1
11.0.6
10.12.4
10.11.8
Credits
Juho Forsén
References
mattermost.com/security-updates
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.