PT-2023-22808 · Discourse · Discourse-Reactions

·

CVE-2023-30611

·

Publicado

2023-04-19

·

Atualizado

2023-05-01

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Discourse-reactions versions prior to 0.3
Description The Discourse-reactions plugin for the Discourse messaging platform has an issue where data about reactions performed on a post in a private topic could be leaked. This affects the confidentiality of user interactions within private topics.
Recommendations For versions prior to 0.3, upgrade to version 0.3 to fully resolve the issue. For users unable to upgrade, disable the discourse-reactions plugin as a temporary workaround to mitigate the issue.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-30611
GHSA-4CGC-C7VH-94G6

Produtos afetados

Discourse-Reactions