CVE-2023-49098: Reaction data for user notifications exposed in Discourse-reactions
Published Jan 12, 2024
·Updated
Discourse-reactions is a plugin that allows user to add their reactions to the post. Data about a user's reaction notifications could be exposed. This vulnerability was patched in commit 2c26939.
Affected Software
1 affected component
Discourse Discourse Reactions Discourse<=0.4
Remediation
Event History
Jan 12, 2024
CVE Published
via MITRE·08:37 PM
Data Sourced
via MITRE·08:37 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-49098?
CVE-2023-49098 is classified as a vulnerability with the potential to expose user reaction notifications.
2
How do I fix CVE-2023-49098?
To fix CVE-2023-49098, update the Discourse Reactions plugin to version 0.4 or later.
3
Which versions are affected by CVE-2023-49098?
CVE-2023-49098 affects all versions of the Discourse Reactions plugin up to and including 0.4.
4
What component does CVE-2023-49098 involve?
CVE-2023-49098 involves the Discourse Reactions plugin for the Discourse platform.
5
Is user data at risk due to CVE-2023-49098?
Yes, CVE-2023-49098 could lead to exposure of data related to user reaction notifications.