First published: Tue Jan 18 2022(Updated: )
Mattermost Boards plugin v0.10.0 and earlier fails to invalidate a session on the server-side when a user logged out of Boards, which allows an attacker to reuse old session token for authorization.
Credit: responsibledisclosure@mattermost.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mattermost Boards | <=0.10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-37866 is classified as a critical vulnerability due to its potential impact on user session security.
To fix CVE-2021-37866, upgrade the Mattermost Boards plugin to version 0.10.1 or later.
CVE-2021-37866 exploits the failure to invalidate a session on the server-side after a user logs out.
If CVE-2021-37866 is not addressed, attackers may reuse old session tokens to gain unauthorized access.
CVE-2021-37866 specifically affects Mattermost Boards plugin version 0.10.0 and earlier.