Description
Mattermost Boards plugin v0.10.0 and earlier fails to invalidate a session on the server-side when a user logged out of Boards, which allows an attacker to reuse old session token for authorization.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-24344 | Mattermost Boards plugin v0.10.0 and earlier fails to invalidate a session on the server-side when a user logged out of Boards, which allows an attacker to reuse old session token for authorization. |
References
History
Fri, 06 Dec 2024 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-12-06T23:11:40.140Z
Reserved: 2021-08-02T00:00:00.000Z
Link: CVE-2021-37866
Updated: 2024-08-04T01:30:08.497Z
Status : Modified
Published: 2022-01-18T17:15:08.503
Modified: 2024-11-21T06:16:01.663
Link: CVE-2021-37866
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD