CVE-2023-25169

discourse-yearly-review is a discourse plugin which publishes an automated Year in Review topic. In affected versions a user present in a yearly review topic that is then anonymised will still have some data linked to its original account. This issue has been patched in commit `b3ab33bbf7` which is included in the latest version of the Discourse Yearly Review plugin. Users are advised to upgrade. Users unable to upgrade may disable the `yearly_review_enabled` setting to fully mitigate the issue. Also, it's possible to edit the anonymised user's old data in the yearly review topics manually.
Configurations

Configuration 1 (hide)

cpe:2.3:a:discourse:discourse_yearly_review:*:*:*:*:*:discourse:*:*

History

13 Mar 2023, 17:51

Type Values Removed Values Added
CPE cpe:2.3:a:discourse:discourse_yearly_review:*:*:*:*:*:discourse:*:*
CWE CWE-200 NVD-CWE-noinfo
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
References (MISC) https://github.com/discourse/discourse-yearly-review/commit/b3ab33bbf7130fca54764cf0336395a8a1eeaf3c - (MISC) https://github.com/discourse/discourse-yearly-review/commit/b3ab33bbf7130fca54764cf0336395a8a1eeaf3c - Patch
References (MISC) https://github.com/discourse/discourse-yearly-review/security/advisories/GHSA-x2r8-v85c-x3x7 - (MISC) https://github.com/discourse/discourse-yearly-review/security/advisories/GHSA-x2r8-v85c-x3x7 - Mitigation, Vendor Advisory
First Time Discourse
Discourse discourse Yearly Review

06 Mar 2023, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-03-06 18:15

Updated : 2023-12-10 14:48


NVD link : CVE-2023-25169

Mitre link : CVE-2023-25169

CVE.ORG link : CVE-2023-25169


JSON object : View

Products Affected

discourse

  • discourse_yearly_review
CWE
NVD-CWE-noinfo CWE-200

Exposure of Sensitive Information to an Unauthorized Actor