CVE-2022-35921 – fof/byobu
Package
Manager: composer
Name: fof/byobu
Vulnerable Version: >=0.3.0-beta.2 <1.1.7
Severity
Level: Low
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00159 pctl0.37332
Details
Byobu user preference to prevent private discussions being started are not respected ### Impact Users electing to prevent others starting private discussions with themselves. > Please note that admins and others with appropriate permissions can always bypass this preference, as was the case before. ### Patches Users of Byobu should update the extension to version 1.1.7, where this has been patched. **This version is only supported on v1.2.0 and later of Flarum Core.** Users of Byobu with Flarum 1.0 or 1.1 should upgrade to Flarum 1.2 or later, or evaluate the impact this issue has on your forum's users and choose to disable the extension if needed. ### Workarounds There are no workarounds for this issue.
Metadata
Created: 2022-08-06T05:20:52Z
Modified: 2022-08-06T05:20:52Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/08/GHSA-6gjm-6wj6-4px5/GHSA-6gjm-6wj6-4px5.json
CWE IDs: ["CWE-269", "CWE-863"]
Alternative ID: GHSA-6gjm-6wj6-4px5
Finding: F159
Auto approve: 1