VulnerabilityModified
CVE-2021-41140
Discourse-reactions is a plugin for the Discourse platform that allows user to add their reactions to the post.
MEDIUM 5.3EPSS 0.93%
Does this matter?
Lower severity and a low EPSS score (0.93%). Track it; it rarely justifies an emergency change on its own.
Description
Discourse-reactions is a plugin for the Discourse platform that allows user to add their reactions to the post. In affected versions reactions given by user to secure topics and private messages are visible. This issue is patched in version 0.2 of discourse-reaction. Users who are unable to update are advised to disable the Discourse-reactions plugin in admin panel.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.93% probability · 59th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-668, CWE-200
- Affected
- discourse/discourse reactions
- Source
- security-advisories@github.com
References
- https://github.com/discourse/discourse-reactions/commit/213d90b82fd15c4186ebc290fee18817d9727d0dPatch, Third Party Advisory
- https://github.com/discourse/discourse-reactions/security/advisories/GHSA-9358-hwg5-jrmhThird Party Advisory
- https://github.com/discourse/discourse-reactions/commit/213d90b82fd15c4186ebc290fee18817d9727d0dPatch, Third Party Advisory
- https://github.com/discourse/discourse-reactions/security/advisories/GHSA-9358-hwg5-jrmhThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.