Mattermost doesn't verify that post actions invoking `/share-issue-publicly` were created by the Jira plugin
Moderate severity
GitHub Reviewed
Published
Dec 24, 2025
to the GitHub Advisory Database
•
Updated Dec 26, 2025
Package
Affected versions
>= 10.11.0, < 10.11.8
>= 10.12.0, < 10.12.4
>= 11.0.0, < 11.0.6
>= 11.1.0, < 11.1.1
Patched versions
10.11.8
10.12.4
11.0.6
11.1.1
< 8.0.0-20251121122154-b57c297c6d7
8.0.0-20251121122154-b57c297c6d7
Description
Published by the National Vulnerability Database
Dec 24, 2025
Published to the GitHub Advisory Database
Dec 24, 2025
Reviewed
Dec 26, 2025
Last updated
Dec 26, 2025
Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fail to verify that post actions invoking /share-issue-publicly were created by the Jira plugin which allowed a malicious Mattermost user to exfiltrate Jira tickets when victim users interacted with affected posts
References