NIXPKGS-2026-0677
GitHub issue
published on
by @mweinelt Activity log
- Created suggestion
- @mweinelt accepted
-
@mweinelt
ignored
6 packages
- discourseAllPlugins
- discourse-mail-receiver
- python312Packages.pydiscourse
- python313Packages.pydiscourse
- python314Packages.pydiscourse
- grafanaPlugins.grafana-discourse-datasource
- @mweinelt published on GitHub
Discourse hasUnauthorized Exposure of Private User Action Types
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a user could access another user's private activity due to insufficient authorization checks in the user actions endpoint. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a patch.
References
-
https://github.com/discourse/discourse/security/advisories/GHSA-ww5f-24g5-c33g x_refsource_CONFIRM
Affected products
discourse
- ==>= 2026.1.0-latest, < 2026.1.2
- === 2026.3.0-latest.1
- ==>= 2026.2.0-latest, < 2026.2.1
Matching in nixpkgs
Ignored packages (6)
pkgs.discourseAllPlugins
Discourse is an open source discussion platform
pkgs.discourse-mail-receiver
Helper program which receives incoming mail for Discourse
pkgs.python312Packages.pydiscourse
Python library for working with Discourse
pkgs.python313Packages.pydiscourse
Python library for working with Discourse
pkgs.python314Packages.pydiscourse
Python library for working with Discourse
pkgs.grafanaPlugins.grafana-discourse-datasource
Allows users to search and view topics, posts, users, tags, categories, and reports on a given Discourse forum through Grafana
Package maintainers
-
@talyz Kim Lindberger <kim.lindberger@gmail.com>