First published: Mon Mar 06 2023(Updated: )
discourse-yearly-review is a discourse plugin which publishes an automated Year in Review topic. In affected versions a user present in a yearly review topic that is then anonymised will still have some data linked to its original account. This issue has been patched in commit `b3ab33bbf7` which is included in the latest version of the Discourse Yearly Review plugin. Users are advised to upgrade. Users unable to upgrade may disable the `yearly_review_enabled` setting to fully mitigate the issue. Also, it's possible to edit the anonymised user's old data in the yearly review topics manually.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Discourse Discourse Yearly Review | <0.2 |
https://github.com/discourse/discourse-yearly-review/commit/b3ab33bbf7130fca54764cf0336395a8a1eeaf3c
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-25169 is a vulnerability in the discourse-yearly-review plugin that allows data to remain linked to an anonymized account in a Year in Review topic.
CVE-2023-25169 has a severity score of 5.3, which is considered medium.
In affected versions of discourse-yearly-review (up to and excluding 0.2), a user present in a Year in Review topic that is then anonymized may still have some data linked to their original account.
Yes, a patch for CVE-2023-25169 has been released in commit b3ab33bbf7.
You can find more information about CVE-2023-25169 on the GitHub security advisory page at https://github.com/discourse/discourse-yearly-review/security/advisories/GHSA-x2r8-v85c-x3x7.