Discourse-reactions is a plugin that allows user to add their reactions to the post in the Discourse messaging platform. In affected versions data about what reactions were performed on a post in a private topic could be leaked. This issue has been addressed in version 0.3. Users are advised to upgrade. Users unable to upgrade should disable the discourse-reactions plugin to fully mitigate the issue.
References
Configurations
History
No history.
Information
Published : 2023-04-19 18:15
Updated : 2023-05-01 18:12
NVD link : CVE-2023-30611
Mitre link : CVE-2023-30611
CVE.ORG link : CVE-2023-30611
JSON object : View
Products Affected
discourse
- reactions
CWE