First published: Tue Oct 19 2021(Updated: )
Discourse-reactions is a plugin for the Discourse platform that allows user to add their reactions to the post. In affected versions reactions given by user to secure topics and private messages are visible. This issue is patched in version 0.2 of discourse-reaction. Users who are unable to update are advised to disable the Discourse-reactions plugin in admin panel.
Credit: security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Discourse Reactions | <0.2 |
https://github.com/discourse/discourse-reactions/commit/213d90b82fd15c4186ebc290fee18817d9727d0d
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-41140 is a moderate severity vulnerability affecting the Discourse Reactions plugin.
To fix CVE-2021-41140, upgrade to version 0.2 or later of the Discourse Reactions plugin.
CVE-2021-41140 enables user reactions to secure topics and private messages to be visible to unauthorized users.
CVE-2021-41140 affects all versions of Discourse Reactions prior to version 0.2.
Yes, a patch for CVE-2021-41140 was included in version 0.2 of the Discourse Reactions plugin.