CVE-2021-37867

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
18/01/2022
Last modified:
24/01/2022

Description

Mattermost Boards plugin v0.10.0 and earlier fails to protect email addresses of all users via one of the Boards APIs, which allows authenticated and unauthorized users to access this information resulting in sensitive & private information disclosure.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mattermost:mattermost_boards:*:*:*:*:*:*:*:* 0.10.0 (including)


References to Advisories, Solutions, and Tools