First published: Wed Apr 19 2023(Updated: )
Discourse-reactions is a plugin that allows user to add their reactions to the post in the Discourse messaging platform. In affected versions data about what reactions were performed on a post in a private topic could be leaked. This issue has been addressed in version 0.3. Users are advised to upgrade. Users unable to upgrade should disable the discourse-reactions plugin to fully mitigate the issue.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Discourse Reactions | =0.2 |
https://github.com/discourse/discourse-reactions/commit/01aca15b2774c088f3673118e92e9469f37d2fb6
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-30611.
The severity of CVE-2023-30611 is medium, with a severity value of 5.3.
The affected software is Discourse Reactions plugin version 0.2.
To fix this vulnerability, upgrade to version 0.3 of the Discourse Reactions plugin.
You can find more information about this vulnerability at the following references: [1] [2].