PT-2021-23123 · Discourse · Discourse-Reactions

Jomaxro

·

Published

2021-10-19

·

Updated

2022-08-12

·

CVE-2021-41140

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Discourse-reactions versions prior to 0.2
Description The issue affects the Discourse-reactions plugin, allowing reactions to secure topics and private messages to be visible. This affects the confidentiality of user interactions within the platform.
Recommendations For versions prior to 0.2, update to version 0.2 to resolve the issue. As a temporary workaround for users unable to update, disable the Discourse-reactions plugin in the admin panel.

Fix

Information Disclosure

Exposure of Resource to Wrong Sphere

Weakness Enumeration

Related Identifiers

CVE-2021-41140
GHSA-9358-HWG5-JRMH

Affected Products

Discourse-Reactions