Vulnerability in Mattermost's Jira Plugin Allows Unauthenticated Access
CVE-2025-64641

4.1MEDIUM

Key Information:

Vendor

Mattermost

Vendor
CVE Published:
24 December 2025

What is CVE-2025-64641?

Certain versions of Mattermost fail to properly verify that actions initiated through the /share-issue-publicly endpoint are legitimate and originate from the Jira plugin. This oversight allows a malicious user to craft posts that, when interacted with by other users, can result in unauthorized exfiltration of Jira tickets. This vulnerability highlights a significant security gap in user interactions within Mattermost, allowing for potentially sensitive information to be disclosed without proper authorization.

Affected Version(s)

Mattermost 11.1.0

Mattermost 11.0.0 <= 11.0.5

Mattermost 10.12.0 <= 10.12.3

References

CVSS V3.1

Score:
4.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Juho Forsén
.
CVE-2025-64641 : Vulnerability in Mattermost's Jira Plugin Allows Unauthenticated Access