NIXPKGS-2026-0677
GitHub issue
published 3 months ago
by @mweinelt Activity log
- Created suggestion
- @mweinelt accepted
-
@mweinelt
ignored
6 packages
- discourseAllPlugins
- discourse-mail-receiver
- python312Packages.pydiscourse
- python313Packages.pydiscourse
- python314Packages.pydiscourse
- grafanaPlugins.grafana-discourse-datasource
- @mweinelt published on GitHub
Discourse hasUnauthorized Exposure of Private User Action Types
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a user could access another user's private activity due to insufficient authorization checks in the user actions endpoint. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a patch.
References
-
https://github.com/discourse/discourse/security/advisories/GHSA-ww5f-24g5-c33g x_refsource_CONFIRM
Affected products
discourse
- === 2026.3.0-latest.1
- ==>= 2026.1.0-latest, < 2026.1.2
- ==>= 2026.2.0-latest, < 2026.2.1
Matching in nixpkgs
Ignored packages (6)
pkgs.discourseAllPlugins
Open source discussion platform
pkgs.discourse-mail-receiver
Helper program which receives incoming mail for Discourse
pkgs.python312Packages.pydiscourse
None
pkgs.python313Packages.pydiscourse
Python library for working with Discourse
pkgs.python314Packages.pydiscourse
Python library for working with Discourse
pkgs.grafanaPlugins.grafana-discourse-datasource
Allows users to search and view topics, posts, users, tags, categories, and reports on a given Discourse forum through Grafana
Package maintainers
-
@talyz Kim Lindberger <kim.lindberger@gmail.com>