High severity7.5NVD Advisory· Published Jun 30, 2021· Updated Jun 17, 2026
CVE-2021-35970
CVE-2021-35970
Description
Talk 4 in Coral before 4.12.1 allows remote attackers to discover e-mail addresses and other sensitive information via GraphQL because permission checks use an incorrect data type.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Coral/Talk 4description
- Range: <4.12.1
Patches
Vulnerability mechanics
References
4- github.com/coralproject/talk/compare/v4.12.0...v4.12.1nvdPatchThird Party Advisory
- github.com/coralproject/talk/pull/3599nvdPatchThird Party Advisory
- docs.coralproject.net/coral/api/graphql/nvdExploitVendor Advisory
- github.com/coralproject/talk/issues/3600nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.