CVE-2023-30611
Discourse-reactions is a plugin that allows user to add their reactions to the post in the Discourse messaging platform.
Does this matter?
Lower severity and a low EPSS score (0.43%). Track it; it rarely justifies an emergency change on its own.
Description
Discourse-reactions is a plugin that allows user to add their reactions to the post in the Discourse messaging platform. In affected versions data about what reactions were performed on a post in a private topic could be leaked. This issue has been addressed in version 0.3. Users are advised to upgrade. Users unable to upgrade should disable the discourse-reactions plugin to fully mitigate the issue.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.43% probability · 36th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- discourse/reactions
- Source
- security-advisories@github.com
References
- https://github.com/discourse/discourse-reactions/commit/01aca15b2774c088f3673118e92e9469f37d2fb6Patch
- https://github.com/discourse/discourse-reactions/security/advisories/GHSA-4cgc-c7vh-94g6Vendor Advisory
- https://github.com/discourse/discourse-reactions/commit/01aca15b2774c088f3673118e92e9469f37d2fb6Patch
- https://github.com/discourse/discourse-reactions/security/advisories/GHSA-4cgc-c7vh-94g6Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.