CVE-2021-37866 - CVE House
Back to Database
Status published Medium CVE-2021-37866

Session is not invalidated on server-side when user logged out of Boards

Vulnerability Description

Mattermost Boards plugin v0.10.0 and earlier fails to invalidate a session on the server-side when a user logged out of Boards, which allows an attacker to reuse old session token for authorization.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-37866

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Hagai Wechsler from WhiteSource

Affected Vendor

Affected Software

Mattermost Boards
Vulnerable Versions:
unspecified, 0.9.5, 0.8.4, 0.7.5

Timeline

Official Publish: January 18th, 2022
Last Modified: December 6th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N

Weaknesses (CWE)