CVE-2023-25169

discourse-yearly-review is a discourse plugin which publishes an automated Year in Review topic. In affected versions a user present in a yearly review topic that is then anonymised will still have some data linked to its original account. This issue has been patched in commit `b3ab33bbf7` which is included in the latest version of the Discourse Yearly Review plugin. Users are advised to upgrade. Users unable to upgrade may disable the `yearly_review_enabled` setting to fully mitigate the issue. Also, it's possible to edit the anonymised user's old data in the yearly review topics manually.
Configurations

Configuration 1 (hide)

cpe:2.3:a:discourse:discourse_yearly_review:*:*:*:*:*:discourse:*:*

History

21 Nov 2024, 07:49

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 5.3
v2 : unknown
v3 : 3.1
References () https://github.com/discourse/discourse-yearly-review/commit/b3ab33bbf7130fca54764cf0336395a8a1eeaf3c - Patch () https://github.com/discourse/discourse-yearly-review/commit/b3ab33bbf7130fca54764cf0336395a8a1eeaf3c - Patch
References () https://github.com/discourse/discourse-yearly-review/security/advisories/GHSA-x2r8-v85c-x3x7 - Mitigation, Vendor Advisory () https://github.com/discourse/discourse-yearly-review/security/advisories/GHSA-x2r8-v85c-x3x7 - Mitigation, Vendor Advisory

13 Mar 2023, 17:51

Type Values Removed Values Added
References (MISC) https://github.com/discourse/discourse-yearly-review/commit/b3ab33bbf7130fca54764cf0336395a8a1eeaf3c - (MISC) https://github.com/discourse/discourse-yearly-review/commit/b3ab33bbf7130fca54764cf0336395a8a1eeaf3c - Patch
References (MISC) https://github.com/discourse/discourse-yearly-review/security/advisories/GHSA-x2r8-v85c-x3x7 - (MISC) https://github.com/discourse/discourse-yearly-review/security/advisories/GHSA-x2r8-v85c-x3x7 - Mitigation, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CPE cpe:2.3:a:discourse:discourse_yearly_review:*:*:*:*:*:discourse:*:*
CWE CWE-200 NVD-CWE-noinfo

06 Mar 2023, 19:14

Type Values Removed Values Added
New CVE

Information

Published : 2023-03-06 18:15

Updated : 2024-11-21 07:49


NVD link : CVE-2023-25169

Mitre link : CVE-2023-25169

CVE.ORG link : CVE-2023-25169


JSON object : View

Products Affected

discourse

  • discourse_yearly_review
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

NVD-CWE-noinfo