CVE-2021-37867: Emails of all users are exposed via one of the Boards APIs
Mattermost Boards plugin v0.10.0 and earlier fails to protect email addresses of all users via one of the Boards APIs, which allows authenticated and unauthorized users to access this information resulting in sensitive & private information disclosure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-37867?
CVE-2021-37867 is classified as a medium-severity vulnerability due to the potential for sensitive information disclosure.
How do I fix CVE-2021-37867?
To mitigate CVE-2021-37867, upgrade the Mattermost Boards plugin to version 0.10.1 or later.
Who is affected by CVE-2021-37867?
CVE-2021-37867 affects all users of Mattermost Boards plugin versions 0.10.0 and earlier.
What information is exposed due to CVE-2021-37867?
CVE-2021-37867 allows both authenticated and unauthorized users to access email addresses of all users.
Is there a workaround for CVE-2021-37867 until I can upgrade?
There are no specific workarounds for CVE-2021-37867; the best protection is to upgrade to the fixed version.