CVE-2023-30611: Reaction metadata exposed in private topics in Discourse-reactions
Discourse-reactions is a plugin that allows user to add their reactions to the post in the Discourse messaging platform. In affected versions data about what reactions were performed on a post in a private topic could be leaked. This issue has been addressed in version 0.3. Users are advised to upgrade. Users unable to upgrade should disable the discourse-reactions plugin to fully mitigate the issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-30611.
What is the severity of CVE-2023-30611?
The severity of CVE-2023-30611 is medium, with a severity value of 5.3.
What is the affected software?
The affected software is Discourse Reactions plugin version 0.2.
How can I fix this vulnerability?
To fix this vulnerability, upgrade to version 0.3 of the Discourse Reactions plugin.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability at the following references: [1] [2].