logo

CVE-2022-35921 fof/byobu

Package

Manager: composer
Name: fof/byobu
Vulnerable Version: >=0.3.0-beta.2 <1.1.7

Severity

Level: Low

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

EPSS: 0.00159 pctl0.37332

Details

Byobu user preference to prevent private discussions being started are not respected ### Impact Users electing to prevent others starting private discussions with themselves. > Please note that admins and others with appropriate permissions can always bypass this preference, as was the case before. ### Patches Users of Byobu should update the extension to version 1.1.7, where this has been patched. **This version is only supported on v1.2.0 and later of Flarum Core.** Users of Byobu with Flarum 1.0 or 1.1 should upgrade to Flarum 1.2 or later, or evaluate the impact this issue has on your forum's users and choose to disable the extension if needed. ### Workarounds There are no workarounds for this issue.

Metadata

Created: 2022-08-06T05:20:52Z
Modified: 2022-08-06T05:20:52Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/08/GHSA-6gjm-6wj6-4px5/GHSA-6gjm-6wj6-4px5.json
CWE IDs: ["CWE-269", "CWE-863"]
Alternative ID: GHSA-6gjm-6wj6-4px5
Finding: F159
Auto approve: 1