discourse/discourse-policy

discourse/discourse-policy

Releases0
Stars8

CVE History

CVEPublishedCVSS v3CVSS v2
3.5 LOW

Discourse Policy plugin gives the ability to confirm users have seen or done something. Prior to version 0.1.1, if there was a policy posted to a public topic that was tied to a private group then the group members could be shown to non-group members. This issue has been patched in version 0.1.1. A workaround involves moving any policy topics with private groups to restricted categories.