Discourse Policy plugin gives the ability to confirm users have seen or done something. Prior to version 0.1.1, if there was a policy posted to a public topic that was tied to a private group then the group members could be shown to non-group members. This issue has been patched in version 0.1.1. A workaround involves moving any policy topics with private groups to restricted categories.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 30 May 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 29 May 2025 19:30:00 +0000

Type Values Removed Values Added
Description Discourse Policy plugin gives the ability to confirm users have seen or done something. Prior to version 0.1.1, if there was a policy posted to a public topic that was tied to a private group then the group members could be shown to non-group members. This issue has been patched in version 0.1.1. A workaround involves moving any policy topics with private groups to restricted categories.
Title Discourse Policy plugin private group members visible
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-05-30T12:35:34.217Z

Reserved: 2025-05-05T16:53:10.374Z

Link: CVE-2025-47288

cve-icon Vulnrichment

Updated: 2025-05-30T12:35:31.588Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-29T20:15:27.283

Modified: 2025-05-30T16:31:03.107

Link: CVE-2025-47288

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.