Discourse Reactions Plugin Exposes Whisper Content on /u/:usr activity
CVE-2024-31219 Published on April 15, 2024
Discourse-reactions' reaction data and public topic whisper content exposed on reactions given user activity page
Discourse-reactions is a plugin that allows user to add their reactions to the post. When whispers are enabled on a site via `whispers_allowed_groups` and reactions are made on whispers on public topics, the contents of the whisper and the reaction data are shown on the `/u/:username/activity/reactions` endpoint.
Vulnerability Analysis
CVE-2024-31219 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality, a small impact on integrity and availability.
Weakness Type
What is an Information Disclosure Vulnerability?
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVE-2024-31219 has been classified to as an Information Disclosure vulnerability or weakness.
Products Associated with CVE-2024-31219
Want to know whenever a new CVE is published for Discourse? stack.watch will email you.
Affected Versions
discourse-reactions Version < 0.5 is affected by CVE-2024-31219Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.