CVE-2021-37867

MEDIUM

Mattermost Boards < 0.10.0 - Authenticated Sensitive Information Exposure via API

Title source: llm
STIX 2.1

Description

Mattermost Boards plugin v0.10.0 and earlier fails to protect email addresses of all users via one of the Boards APIs, which allows authenticated and unauthorized users to access this information resulting in sensitive & private information disclosure.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_misc
https://mattermost.com/security-updates/

Scores

CVSS v3 4.3
EPSS 0.0023
EPSS Percentile 45.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
mattermost/mattermost_boards < 0.10.0
Published Jan 18, 2022
Tracked Since Feb 18, 2026