Session is not invalidated on server-side when user logged out of Boards
CVE-2021-37866
4.7MEDIUM
What is CVE-2021-37866?
Mattermost Boards plugin v0.10.0 and earlier fails to invalidate a session on the server-side when a user logged out of Boards, which allows an attacker to reuse old session token for authorization.
Affected Version(s)
Mattermost Boards <= 0.10.0
Mattermost Boards 0.9.5
Mattermost Boards 0.8.4