Skip to content

Reactions leak for secure category topics and private messages

Moderate
jomaxro published GHSA-9358-hwg5-jrmh Oct 19, 2021

Package

discourse-reactions (Discourse)

Affected versions

stable <= 0.1

Patched versions

stable >= 0.2

Description

Impact

Reactions given by user to secure topics and private messages are visible.

Patches

This issue is patched in the latest versions of discourse-reaction.

Workarounds

Disable plugin in admin panel.

Severity

Moderate
5.3
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CVE ID

CVE-2021-41140

Weaknesses

No CWEs