Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6gjm-6wj6-4px5

Опубликовано: 06 авг. 2022
Источник: github
Github: Прошло ревью
CVSS3: 3.5

Описание

Byobu user preference to prevent private discussions being started are not respected

Impact

Users electing to prevent others starting private discussions with themselves.

Please note that admins and others with appropriate permissions can always bypass this preference, as was the case before.

Patches

Users of Byobu should update the extension to version 1.1.7, where this has been patched. This version is only supported on v1.2.0 and later of Flarum Core.

Users of Byobu with Flarum 1.0 or 1.1 should upgrade to Flarum 1.2 or later, or evaluate the impact this issue has on your forum's users and choose to disable the extension if needed.

Workarounds

There are no workarounds for this issue.

Пакеты

Наименование

fof/byobu

composer
Затронутые версииВерсия исправления

>= 0.3.0-beta.2, < 1.1.7

1.1.7

EPSS

Процентиль: 38%
0.00168
Низкий

3.5 Low

CVSS3

Дефекты

CWE-269
CWE-863

Связанные уязвимости

CVSS3: 3.5
nvd
больше 3 лет назад

fof/byobu is a private discussions extension for Flarum forum. Affected versions were found to not respect private discussion disablement by users. Users of Byobu should update the extension to version 1.1.7, where this has been patched. Users of Byobu with Flarum 1.0 or 1.1 should upgrade to Flarum 1.2 or later, or evaluate the impact this issue has on your forum's users and choose to disable the extension if needed. There are no workarounds for this issue.

EPSS

Процентиль: 38%
0.00168
Низкий

3.5 Low

CVSS3

Дефекты

CWE-269
CWE-863