Discourse-reactions is a plugin that allows user to add their reactions to the post in the Discourse messaging platform. In affected versions data about what reactions were performed on a post in a private topic could be leaked. This issue has been addressed in version 0.3. Users are advised to upgrade. Users unable to upgrade should disable the discourse-reactions plugin to fully mitigate the issue.
References
Configurations
History
21 Nov 2024, 08:00
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
References | () https://github.com/discourse/discourse-reactions/commit/01aca15b2774c088f3673118e92e9469f37d2fb6 - Patch | |
References | () https://github.com/discourse/discourse-reactions/security/advisories/GHSA-4cgc-c7vh-94g6 - Vendor Advisory |
Information
Published : 2023-04-19 18:15
Updated : 2024-11-21 08:00
NVD link : CVE-2023-30611
Mitre link : CVE-2023-30611
CVE.ORG link : CVE-2023-30611
JSON object : View
Products Affected
discourse
- reactions
CWE