Skip to content

Presence of restricted personal messages may be leaked if tagged with a tag

Low
jomaxro published GHSA-rf8j-mf8c-82v7 Mar 16, 2023

Package

Discourse (Discourse)

Affected versions

stable <= 3.0.1; beta <= 3.1.0.beta2; tests-passed <= 3.1.0.beta2

Patched versions

stable > 3.0.1; beta > 3.1.0.beta2; tests-passed > 3.1.0.beta2

Description

Impact

Currently, the count of personal messages displayed for a tag is a count of all personal messages regardless of whether the personal message is visible to a given user. As a result, any users can technically poll a sensitive tag to determine if a new personal message is created even if the user does not have access to the personal message.

Patches

In the patched versions, the count of personal messages tagged with a given tag is hidden by default. To revert to the old behaviour of displaying the count of personal messages for a given tag, an admin may enable the display_personal_messages_tag_counts site setting.

Severity

Low
3.5
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

CVE ID

CVE-2023-23935

Weaknesses

No CWEs