Presence of restricted personal messages may be leaked if tagged with a tag
Package
Discourse
(Discourse)
Affected versions
stable <= 3.0.1; beta <= 3.1.0.beta2; tests-passed <= 3.1.0.beta2
Patched versions
stable > 3.0.1; beta > 3.1.0.beta2; tests-passed > 3.1.0.beta2
Impact
Currently, the count of personal messages displayed for a tag is a count of all personal messages regardless of whether the personal message is visible to a given user. As a result, any users can technically poll a sensitive tag to determine if a new personal message is created even if the user does not have access to the personal message.
Patches
In the patched versions, the count of personal messages tagged with a given tag is hidden by default. To revert to the old behaviour of displaying the count of personal messages for a given tag, an admin may enable the
display_personal_messages_tag_countssite setting.