CVE-2025-14273: falha de alta gravidade em Mattermost
Mattermost Jira plugin user spoofing enables Jira request forgery.
Publicada em
21Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 7.2epss 0.3%
probabilidade de exploração
0.3%top 83% das CVEs
exploração observada
nãonenhuma fonte reporta
Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 with the Jira plugin enabled and Mattermost Jira plugin versions <=4.4.0 fail to enforce authentication and issue-key path restrictions in the Jira plugin, which allows an unauthenticated attacker who knows a valid user ID to issue authenticated GET and POST requests to the Jira server via crafted plugin payloads that spoof the user ID and inject arbitrary issue key paths. Mattermost Advisory ID: MMSA-2025-00555
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L
Produtos afetados
Mattermost · MattermostCVEs relacionadas — Mattermost
No mesmo produto, das mais perigosas para as menos.
CVE-2025-25279CRITICALArbitrary file read in Mattermost Boards via import & export board archiveEPSS 24.2%CVE-2021-37859HIGHReflected XSS in OAuth FlowEPSS 3.3%CVE-2022-3257LOWServer-side Denial of Service while processing a specifically crafted GIF fileEPSS 1.3%CVE-2022-4044MEDIUMAuthenticated user could send multiple requests containing a large Auto Responder Message payload and can crash a Mattermost serverEPSS 1.1%CVE-2022-3147LOWServer-side Denial of Service while processing a specifically crafted JPEG fileEPSS 1.0%CVE-2022-1982MEDIUMA crafted SVG attachment can crash a Mattermost serverEPSS 0.9%
Referências
https://mattermost.com/security-updates