CVE-2025-14273 Details
Description
Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 with the Jira plugin enabled and Mattermost Jira plugin versions <=4.4.0 fail to enforce authentication and issue-key path restrictions in the Jira plugin, which allows an unauthenticated attacker who knows a valid user ID to issue authenticated GET and POST requests to the Jira server via crafted plugin payloads that spoof the user ID and inject arbitrary issue key paths. Mattermost Advisory ID: MMSA-2025-00555
A vulnerability exists in Mattermost versions 11.1.0, 11.0.5, 10.12.3, and 10.11.7 with the Jira plugin enabled. The issue arises in Jira plugin versions through 4.4.0, where authentication and issue-key path restrictions are not properly enforced. This flaw allows an unauthenticated attacker who knows a valid user ID to send authenticated GET and POST requests to the Jira server. Exploitation involves crafting plugin payloads that spoof the user ID and inject arbitrary issue key paths.
Users can upgrade to Mattermost versions 11.2.0, 11.1.8, 11.0.6, or 10.12.4, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 22, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://mattermost.com/security-updates | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-303 | Incorrect Implementation of Authentication Algorithm | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| mattermost mattermost server | >= 10.11.0, < 10.11.8 >= 10.12.0, < 10.12.4 >= 11.0.0, < 11.0.6 >= 11.1.0, < 11.1.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 29, 2025 | Initial Analysis | [email protected] |
| Dec 22, 2025 | New CVE Received | [email protected] |