Skip to content

x/vulndb: potential Go vuln in github.com/mattermost/mattermost-server: GHSA-fmqf-pmcm-8cx9 #4259

@GoVulnBot

Description

@GoVulnBot

Advisory GHSA-fmqf-pmcm-8cx9 references a vulnerability in the following Go modules:

Module
github.com/mattermost/mattermost-server
github.com/mattermost/mattermost-server

Description:
Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fails to validate user channel membership when attaching Mattermost posts as comments to Jira issues, which allows an authenticated attacker with access to the Jira plugin to read post content and attachments from channels they do not have access to.

References:

Cross references:

See doc/quickstart.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/mattermost/mattermost-server
      non_go_versions:
        - fixed: 8.0.0-20251121122154-b57c297c6d7
      vulnerable_at: 11.2.1+incompatible
    - module: github.com/mattermost/mattermost-server
      versions:
        - introduced: 10.11.0+incompatible
        - fixed: 10.11.8+incompatible
        - introduced: 10.12.0+incompatible
        - fixed: 10.12.4+incompatible
        - fixed: 11.0.6+incompatible
        - introduced: 11.1.0+incompatible
        - fixed: 11.1.1+incompatible
      non_go_versions:
        - introduced: 11.0.0
      vulnerable_at: 11.1.1-rc2+incompatible
summary: |-
    Mattermost doesn't validate user channel membership when attaching Mattermost
    posts as comments to Jira issues in github.com/mattermost/mattermost-server
cves:
    - CVE-2025-13767
ghsas:
    - GHSA-fmqf-pmcm-8cx9
references:
    - advisory: https://github.com/advisories/GHSA-fmqf-pmcm-8cx9
    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-13767
    - fix: https://github.com/mattermost/mattermost/commit/b57c297c6d7ae6812d85e32a625806ac9555deee
    - fix: https://github.com/mattermost/mattermost/pull/34551
    - web: https://mattermost.com/security-updates
notes:
    - fix: 'module merge error: could not merge versions of module github.com/mattermost/mattermost-server: introduced and fixed versions must alternate'
source:
    id: GHSA-fmqf-pmcm-8cx9
    created: 2025-12-26T19:01:32.007143643Z
review_status: UNREVIEWED

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions