Reaction metadata exposed in private topics in Discourse-reactions
CVE-2023-30611
5.3MEDIUM
What is CVE-2023-30611?
Discourse-reactions is a plugin that allows user to add their reactions to the post in the Discourse messaging platform. In affected versions data about what reactions were performed on a post in a private topic could be leaked. This issue has been addressed in version 0.3. Users are advised to upgrade. Users unable to upgrade should disable the discourse-reactions plugin to fully mitigate the issue.
Affected Version(s)
discourse-reactions >= 0.2, < 0.3