CVE-2021-37866: Session is not invalidated on server-side when user logged out of Boards
Published Jan 18, 2022
·Updated
Mattermost Boards plugin v0.10.0 and earlier fails to invalidate a session on the server-side when a user logged out of Boards, which allows an attacker to reuse old session token for authorization.
Affected Software
1 affected component
Mattermost Mattermost Boards<=0.10.0
Event History
Jan 18, 2022
CVE Published
via MITRE·04:52 PM
Data Sourced
via MITRE·04:52 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-37866?
CVE-2021-37866 is classified as a critical vulnerability due to its potential impact on user session security.
2
How do I fix CVE-2021-37866?
To fix CVE-2021-37866, upgrade the Mattermost Boards plugin to version 0.10.1 or later.
3
What does CVE-2021-37866 exploit?
CVE-2021-37866 exploits the failure to invalidate a session on the server-side after a user logs out.
4
What are the consequences of not addressing CVE-2021-37866?
If CVE-2021-37866 is not addressed, attackers may reuse old session tokens to gain unauthorized access.
5
Does CVE-2021-37866 affect all versions of Mattermost Boards?
CVE-2021-37866 specifically affects Mattermost Boards plugin version 0.10.0 and earlier.