Vulnerability in Mattermost's Jira Plugin Allows Unauthenticated Access
CVE-2025-64641
What is CVE-2025-64641?
Certain versions of Mattermost fail to properly verify that actions initiated through the /share-issue-publicly endpoint are legitimate and originate from the Jira plugin. This oversight allows a malicious user to craft posts that, when interacted with by other users, can result in unauthorized exfiltration of Jira tickets. This vulnerability highlights a significant security gap in user interactions within Mattermost, allowing for potentially sensitive information to be disclosed without proper authorization.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Mattermost 11.1.0
Mattermost 11.0.0 <= 11.0.5
Mattermost 10.12.0 <= 10.12.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved