Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS02Z2ptLTZ3ajYtNHB4Nc4AAt2Y
Byobu user preference to prevent private discussions being started are not respected
Impact
Users electing to prevent others starting private discussions with themselves.
Please note that admins and others with appropriate permissions can always bypass this preference, as was the case before.
Patches
Users of Byobu should update the extension to version 1.1.7, where this has been patched. This version is only supported on v1.2.0 and later of Flarum Core.
Users of Byobu with Flarum 1.0 or 1.1 should upgrade to Flarum 1.2 or later, or evaluate the impact this issue has on your forum's users and choose to disable the extension if needed.
Workarounds
There are no workarounds for this issue.
Permalink: https://github.com/advisories/GHSA-6gjm-6wj6-4px5JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS02Z2ptLTZ3ajYtNHB4Nc4AAt2Y
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Low
Classification: General
Published: over 1 year ago
Updated: 9 months ago
CVSS Score: 3.5
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Identifiers: GHSA-6gjm-6wj6-4px5, CVE-2022-35921
References:
- https://github.com/FriendsOfFlarum/byobu/security/advisories/GHSA-6gjm-6wj6-4px5
- https://nvd.nist.gov/vuln/detail/CVE-2022-35921
- https://github.com/FriendsOfFlarum/byobu/commit/23dcf93a30f948d30c678a96681f7fdefeba5171
- https://github.com/advisories/GHSA-6gjm-6wj6-4px5
Blast Radius: 3.6
Affected Packages
packagist:fof/byobu
Dependent packages: 5Dependent repositories: 11
Downloads: 34,323 total
Affected Version Ranges: >= 0.3.0-beta.2, < 1.1.7
Fixed in: 1.1.7
All affected versions: 0.3.0, 0.3.0-beta.2, 0.3.0-beta.3, 0.3.1, 0.3.2, 0.3.3, 0.3.4, 0.4.0, 0.4.1, 0.4.2, 0.4.3, 0.4.4, 0.4.5, 0.5.0, 0.5.1, 0.5.2, 0.5.3, 0.5.4, 0.5.5, 0.5.6, 0.5.7, 0.5.8, 0.6.0, 0.6.1, 1.0.0, 1.0.1, 1.0.2, 1.1.0, 1.1.1, 1.1.2, 1.1.3, 1.1.4, 1.1.5, 1.1.6
All unaffected versions: 0.1.0, 0.1.1, 0.1.2, 0.2.0, 0.2.1, 0.2.2, 1.1.7, 1.1.8, 1.2.0, 1.2.1, 1.3.0, 1.3.1, 1.3.2, 1.3.3, 1.3.4, 1.3.5, 1.3.6