Unrated severityNVD Advisory· Published Jun 30, 2021· Updated Aug 4, 2024
CVE-2021-35970
CVE-2021-35970
Description
Talk 4 in Coral before 4.12.1 allows remote attackers to discover e-mail addresses and other sensitive information via GraphQL because permission checks use an incorrect data type.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Coral/Talk 4description
Patches
Vulnerability mechanics
References
4- docs.coralproject.net/coral/api/graphql/mitrex_refsource_MISC
- github.com/coralproject/talk/compare/v4.12.0...v4.12.1mitrex_refsource_MISC
- github.com/coralproject/talk/issues/3600mitrex_refsource_MISC
- github.com/coralproject/talk/pull/3599mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.