Mattermost Jira plugin crafted action leaks Jira issue details
Vulnerability Description
Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fail to verify that post actions invoking /share-issue-publicly were created by the Jira plugin which allowed a malicious Mattermost user to exfiltrate Jira tickets when victim users interacted with affected posts
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-64641
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Juho Forsén
References
More from Mattermost
View All →Affected Vendor
Mattermost
View all reports →