First published: Fri Jan 12 2024(Updated: )
Discourse-reactions is a plugin that allows user to add their reactions to the post. Data about a user's reaction notifications could be exposed. This vulnerability was patched in commit 2c26939.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Discourse Reactions | <=0.4 |
https://github.com/discourse/discourse-reactions/commit/2c26939395177730e492640d71aac68423be84fc
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-49098 is classified as a vulnerability with the potential to expose user reaction notifications.
To fix CVE-2023-49098, update the Discourse Reactions plugin to version 0.4 or later.
CVE-2023-49098 affects all versions of the Discourse Reactions plugin up to and including 0.4.
CVE-2023-49098 involves the Discourse Reactions plugin for the Discourse platform.
Yes, CVE-2023-49098 could lead to exposure of data related to user reaction notifications.