Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS02Z2ptLTZ3ajYtNHB4Nc4AAt2Y

Byobu user preference to prevent private discussions being started are not respected

Impact

Users electing to prevent others starting private discussions with themselves.

Please note that admins and others with appropriate permissions can always bypass this preference, as was the case before.

Patches

Users of Byobu should update the extension to version 1.1.7, where this has been patched. This version is only supported on v1.2.0 and later of Flarum Core.

Users of Byobu with Flarum 1.0 or 1.1 should upgrade to Flarum 1.2 or later, or evaluate the impact this issue has on your forum's users and choose to disable the extension if needed.

Workarounds

There are no workarounds for this issue.

Permalink: https://github.com/advisories/GHSA-6gjm-6wj6-4px5
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS02Z2ptLTZ3ajYtNHB4Nc4AAt2Y
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Low
Classification: General
Published: over 1 year ago
Updated: 9 months ago


CVSS Score: 3.5
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

Identifiers: GHSA-6gjm-6wj6-4px5, CVE-2022-35921
References: Repository: https://github.com/FriendsOfFlarum/byobu
Blast Radius: 3.6

Affected Packages

packagist:fof/byobu
Dependent packages: 5
Dependent repositories: 11
Downloads: 34,323 total
Affected Version Ranges: >= 0.3.0-beta.2, < 1.1.7
Fixed in: 1.1.7
All affected versions: 0.3.0, 0.3.0-beta.2, 0.3.0-beta.3, 0.3.1, 0.3.2, 0.3.3, 0.3.4, 0.4.0, 0.4.1, 0.4.2, 0.4.3, 0.4.4, 0.4.5, 0.5.0, 0.5.1, 0.5.2, 0.5.3, 0.5.4, 0.5.5, 0.5.6, 0.5.7, 0.5.8, 0.6.0, 0.6.1, 1.0.0, 1.0.1, 1.0.2, 1.1.0, 1.1.1, 1.1.2, 1.1.3, 1.1.4, 1.1.5, 1.1.6
All unaffected versions: 0.1.0, 0.1.1, 0.1.2, 0.2.0, 0.2.1, 0.2.2, 1.1.7, 1.1.8, 1.2.0, 1.2.1, 1.3.0, 1.3.1, 1.3.2, 1.3.3, 1.3.4, 1.3.5, 1.3.6