flarum/tags
[READ ONLY] Subtree split of Flarum tags extension.
Activity
- Latest release
- 2w ago
- Total releases
- 56
- Cadence
- ~43 days
- Last 12 months
- 17
Reach
- Stars
- 38
Details
- License
- MIT
- First release
- Nov 02, 2015
| Version | Released | |
|---|---|---|
v2.0.0-rc.8
pre
| ||
v2.0.0-rc.7
pre
| ||
v2.0.0-rc.6
pre
| ||
v2.0.0-rc.5
pre
| ||
v2.0.0-rc.4
pre
| ||
v2.0.0-rc.3
pre
| ||
v2.0.0-rc.2
pre
| ||
v2.0.0-rc.1
pre
| ||
v1.8.8
patch
| ||
v1.8.7
patch
| ||
v2.0.0-beta.8
pre
| ||
v2.0.0-beta.7
pre
| ||
v2.0.0-beta.6
pre
| ||
v1.8.6
patch
| ||
v2.0.0-beta.5
pre
| ||
v2.0.0-beta.4
pre
| ||
v1.8.5
patch
| ||
v2.0.0-beta.3
pre
| ||
v1.8.4
patch
| ||
v2.0.0-beta.2
pre
| ||
v2.0.0-beta.1
pre
| ||
v1.8.3
patch
| ||
v1.8.2
patch
| ||
v1.8.1
patch
| ||
v1.8.0
minor
| ||
v1.7.1
patch
| ||
v1.7.0
minor
| ||
v1.6.1
patch
| ||
v1.6.0
minor
| ||
v1.5.0
minor
| ||
v1.4.0
minor
| ||
v1.3.0
minor
| ||
v1.2.0
minor
| ||
v1.1.0
minor
| ||
v1.0.3
patch
| ||
v1.0.2
patch
| ||
v1.0.1
patch
| ||
v1.0.0
initial
| ||
v0.1.0-beta.16
pre
| ||
v0.1.0-beta.15
pre
| ||
v0.1.0-beta.14
pre
|
v0.1.0-beta.14
pre
Dependencies (1)
Changelog
Compare changes
|
|
v0.1.0-beta.13.2
pre
| ||
v0.1.0-beta.13.1
pre
1 CVE
GHSA-32wx-4gxx-h48f
Jan 29, 2021
Users can edit the tags of any discussion
Medium
This advisory concerns a vulnerability which was patched and publicly released on October 5, 2020. ImpactThis vulnerability allowed any registered user to edit the tags of any discussion for which they have READ access using the REST API. Users were able to remove any existing tag, and add any tag in which they are allowed to create discussions. The chosen tags still had to match the configured Tags minimums and maximums. By moving the discussion to new tags, users were able to go around permissions applied to restricted tags. Depending on the setup, this can include publicly exposing content that was only visible to certain groups, or gain the ability to interact with content where such interaction was limited. The full impact varies depending on the configuration of permissions and restricted tags, and which community extensions are being used. All tag-scoped permissions offered by extensions are impacted by this ability to go around them. Forums that don't use restricted tags and don't use any extension that relies on tags for access control should not see any security impact. An update is still required to stop users from being able to change any discussion's tags. Forums that don't use the Tags extension are unaffected. PatchesThe fix will be available in version v0.1.0-beta.14 with Flarum beta 14. The fix has already been back-ported to Flarum beta 13 as version v0.1.0-beta.13.2 of the Tags extension. WorkaroundsVersion v0.1.0-beta.13.2 of the Tags extension allows existing Flarum beta 13 forums to fix the issue without the need to update to beta 14. Forums that have not yet updated to Flarum beta 13 are encouraged to update as soon as possible. ReferencesFor more informationIf you have any questions or comments about this advisory, please start a new discussion on our support forum. If you discover a security vulnerability within Flarum, please send an e-mail to security@flarum.org. All security vulnerabilities will be promptly addressed. More details can be found in our security policy. Affected versions
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.13.1
v0.1.0-beta.3
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.8
v0.1.0-beta.8.1
+ 2 more Show less
v0.1.0-beta.8.2
v0.1.0-beta.9
Fixed in
0.1.0-beta.13.2
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v0.1.0-beta.13
pre
1 CVE
GHSA-32wx-4gxx-h48f
Jan 29, 2021
Users can edit the tags of any discussion
Medium
This advisory concerns a vulnerability which was patched and publicly released on October 5, 2020. ImpactThis vulnerability allowed any registered user to edit the tags of any discussion for which they have READ access using the REST API. Users were able to remove any existing tag, and add any tag in which they are allowed to create discussions. The chosen tags still had to match the configured Tags minimums and maximums. By moving the discussion to new tags, users were able to go around permissions applied to restricted tags. Depending on the setup, this can include publicly exposing content that was only visible to certain groups, or gain the ability to interact with content where such interaction was limited. The full impact varies depending on the configuration of permissions and restricted tags, and which community extensions are being used. All tag-scoped permissions offered by extensions are impacted by this ability to go around them. Forums that don't use restricted tags and don't use any extension that relies on tags for access control should not see any security impact. An update is still required to stop users from being able to change any discussion's tags. Forums that don't use the Tags extension are unaffected. PatchesThe fix will be available in version v0.1.0-beta.14 with Flarum beta 14. The fix has already been back-ported to Flarum beta 13 as version v0.1.0-beta.13.2 of the Tags extension. WorkaroundsVersion v0.1.0-beta.13.2 of the Tags extension allows existing Flarum beta 13 forums to fix the issue without the need to update to beta 14. Forums that have not yet updated to Flarum beta 13 are encouraged to update as soon as possible. ReferencesFor more informationIf you have any questions or comments about this advisory, please start a new discussion on our support forum. If you discover a security vulnerability within Flarum, please send an e-mail to security@flarum.org. All security vulnerabilities will be promptly addressed. More details can be found in our security policy. Affected versions
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.13.1
v0.1.0-beta.3
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.8
v0.1.0-beta.8.1
+ 2 more Show less
v0.1.0-beta.8.2
v0.1.0-beta.9
Fixed in
0.1.0-beta.13.2
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v0.1.0-beta.12
pre
1 CVE
GHSA-32wx-4gxx-h48f
Jan 29, 2021
Users can edit the tags of any discussion
Medium
This advisory concerns a vulnerability which was patched and publicly released on October 5, 2020. ImpactThis vulnerability allowed any registered user to edit the tags of any discussion for which they have READ access using the REST API. Users were able to remove any existing tag, and add any tag in which they are allowed to create discussions. The chosen tags still had to match the configured Tags minimums and maximums. By moving the discussion to new tags, users were able to go around permissions applied to restricted tags. Depending on the setup, this can include publicly exposing content that was only visible to certain groups, or gain the ability to interact with content where such interaction was limited. The full impact varies depending on the configuration of permissions and restricted tags, and which community extensions are being used. All tag-scoped permissions offered by extensions are impacted by this ability to go around them. Forums that don't use restricted tags and don't use any extension that relies on tags for access control should not see any security impact. An update is still required to stop users from being able to change any discussion's tags. Forums that don't use the Tags extension are unaffected. PatchesThe fix will be available in version v0.1.0-beta.14 with Flarum beta 14. The fix has already been back-ported to Flarum beta 13 as version v0.1.0-beta.13.2 of the Tags extension. WorkaroundsVersion v0.1.0-beta.13.2 of the Tags extension allows existing Flarum beta 13 forums to fix the issue without the need to update to beta 14. Forums that have not yet updated to Flarum beta 13 are encouraged to update as soon as possible. ReferencesFor more informationIf you have any questions or comments about this advisory, please start a new discussion on our support forum. If you discover a security vulnerability within Flarum, please send an e-mail to security@flarum.org. All security vulnerabilities will be promptly addressed. More details can be found in our security policy. Affected versions
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.13.1
v0.1.0-beta.3
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.8
v0.1.0-beta.8.1
+ 2 more Show less
v0.1.0-beta.8.2
v0.1.0-beta.9
Fixed in
0.1.0-beta.13.2
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v0.1.0-beta.11
pre
1 CVE
GHSA-32wx-4gxx-h48f
Jan 29, 2021
Users can edit the tags of any discussion
Medium
This advisory concerns a vulnerability which was patched and publicly released on October 5, 2020. ImpactThis vulnerability allowed any registered user to edit the tags of any discussion for which they have READ access using the REST API. Users were able to remove any existing tag, and add any tag in which they are allowed to create discussions. The chosen tags still had to match the configured Tags minimums and maximums. By moving the discussion to new tags, users were able to go around permissions applied to restricted tags. Depending on the setup, this can include publicly exposing content that was only visible to certain groups, or gain the ability to interact with content where such interaction was limited. The full impact varies depending on the configuration of permissions and restricted tags, and which community extensions are being used. All tag-scoped permissions offered by extensions are impacted by this ability to go around them. Forums that don't use restricted tags and don't use any extension that relies on tags for access control should not see any security impact. An update is still required to stop users from being able to change any discussion's tags. Forums that don't use the Tags extension are unaffected. PatchesThe fix will be available in version v0.1.0-beta.14 with Flarum beta 14. The fix has already been back-ported to Flarum beta 13 as version v0.1.0-beta.13.2 of the Tags extension. WorkaroundsVersion v0.1.0-beta.13.2 of the Tags extension allows existing Flarum beta 13 forums to fix the issue without the need to update to beta 14. Forums that have not yet updated to Flarum beta 13 are encouraged to update as soon as possible. ReferencesFor more informationIf you have any questions or comments about this advisory, please start a new discussion on our support forum. If you discover a security vulnerability within Flarum, please send an e-mail to security@flarum.org. All security vulnerabilities will be promptly addressed. More details can be found in our security policy. Affected versions
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.13.1
v0.1.0-beta.3
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.8
v0.1.0-beta.8.1
+ 2 more Show less
v0.1.0-beta.8.2
v0.1.0-beta.9
Fixed in
0.1.0-beta.13.2
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v0.1.0-beta.10
pre
1 CVE
GHSA-32wx-4gxx-h48f
Jan 29, 2021
Users can edit the tags of any discussion
Medium
This advisory concerns a vulnerability which was patched and publicly released on October 5, 2020. ImpactThis vulnerability allowed any registered user to edit the tags of any discussion for which they have READ access using the REST API. Users were able to remove any existing tag, and add any tag in which they are allowed to create discussions. The chosen tags still had to match the configured Tags minimums and maximums. By moving the discussion to new tags, users were able to go around permissions applied to restricted tags. Depending on the setup, this can include publicly exposing content that was only visible to certain groups, or gain the ability to interact with content where such interaction was limited. The full impact varies depending on the configuration of permissions and restricted tags, and which community extensions are being used. All tag-scoped permissions offered by extensions are impacted by this ability to go around them. Forums that don't use restricted tags and don't use any extension that relies on tags for access control should not see any security impact. An update is still required to stop users from being able to change any discussion's tags. Forums that don't use the Tags extension are unaffected. PatchesThe fix will be available in version v0.1.0-beta.14 with Flarum beta 14. The fix has already been back-ported to Flarum beta 13 as version v0.1.0-beta.13.2 of the Tags extension. WorkaroundsVersion v0.1.0-beta.13.2 of the Tags extension allows existing Flarum beta 13 forums to fix the issue without the need to update to beta 14. Forums that have not yet updated to Flarum beta 13 are encouraged to update as soon as possible. ReferencesFor more informationIf you have any questions or comments about this advisory, please start a new discussion on our support forum. If you discover a security vulnerability within Flarum, please send an e-mail to security@flarum.org. All security vulnerabilities will be promptly addressed. More details can be found in our security policy. Affected versions
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.13.1
v0.1.0-beta.3
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.8
v0.1.0-beta.8.1
+ 2 more Show less
v0.1.0-beta.8.2
v0.1.0-beta.9
Fixed in
0.1.0-beta.13.2
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v0.1.0-beta.9
pre
1 CVE
GHSA-32wx-4gxx-h48f
Jan 29, 2021
Users can edit the tags of any discussion
Medium
This advisory concerns a vulnerability which was patched and publicly released on October 5, 2020. ImpactThis vulnerability allowed any registered user to edit the tags of any discussion for which they have READ access using the REST API. Users were able to remove any existing tag, and add any tag in which they are allowed to create discussions. The chosen tags still had to match the configured Tags minimums and maximums. By moving the discussion to new tags, users were able to go around permissions applied to restricted tags. Depending on the setup, this can include publicly exposing content that was only visible to certain groups, or gain the ability to interact with content where such interaction was limited. The full impact varies depending on the configuration of permissions and restricted tags, and which community extensions are being used. All tag-scoped permissions offered by extensions are impacted by this ability to go around them. Forums that don't use restricted tags and don't use any extension that relies on tags for access control should not see any security impact. An update is still required to stop users from being able to change any discussion's tags. Forums that don't use the Tags extension are unaffected. PatchesThe fix will be available in version v0.1.0-beta.14 with Flarum beta 14. The fix has already been back-ported to Flarum beta 13 as version v0.1.0-beta.13.2 of the Tags extension. WorkaroundsVersion v0.1.0-beta.13.2 of the Tags extension allows existing Flarum beta 13 forums to fix the issue without the need to update to beta 14. Forums that have not yet updated to Flarum beta 13 are encouraged to update as soon as possible. ReferencesFor more informationIf you have any questions or comments about this advisory, please start a new discussion on our support forum. If you discover a security vulnerability within Flarum, please send an e-mail to security@flarum.org. All security vulnerabilities will be promptly addressed. More details can be found in our security policy. Affected versions
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.13.1
v0.1.0-beta.3
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.8
v0.1.0-beta.8.1
+ 2 more Show less
v0.1.0-beta.8.2
v0.1.0-beta.9
Fixed in
0.1.0-beta.13.2
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v0.1.0-beta.8.2
pre
1 CVE
GHSA-32wx-4gxx-h48f
Jan 29, 2021
Users can edit the tags of any discussion
Medium
This advisory concerns a vulnerability which was patched and publicly released on October 5, 2020. ImpactThis vulnerability allowed any registered user to edit the tags of any discussion for which they have READ access using the REST API. Users were able to remove any existing tag, and add any tag in which they are allowed to create discussions. The chosen tags still had to match the configured Tags minimums and maximums. By moving the discussion to new tags, users were able to go around permissions applied to restricted tags. Depending on the setup, this can include publicly exposing content that was only visible to certain groups, or gain the ability to interact with content where such interaction was limited. The full impact varies depending on the configuration of permissions and restricted tags, and which community extensions are being used. All tag-scoped permissions offered by extensions are impacted by this ability to go around them. Forums that don't use restricted tags and don't use any extension that relies on tags for access control should not see any security impact. An update is still required to stop users from being able to change any discussion's tags. Forums that don't use the Tags extension are unaffected. PatchesThe fix will be available in version v0.1.0-beta.14 with Flarum beta 14. The fix has already been back-ported to Flarum beta 13 as version v0.1.0-beta.13.2 of the Tags extension. WorkaroundsVersion v0.1.0-beta.13.2 of the Tags extension allows existing Flarum beta 13 forums to fix the issue without the need to update to beta 14. Forums that have not yet updated to Flarum beta 13 are encouraged to update as soon as possible. ReferencesFor more informationIf you have any questions or comments about this advisory, please start a new discussion on our support forum. If you discover a security vulnerability within Flarum, please send an e-mail to security@flarum.org. All security vulnerabilities will be promptly addressed. More details can be found in our security policy. Affected versions
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.13.1
v0.1.0-beta.3
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.8
v0.1.0-beta.8.1
+ 2 more Show less
v0.1.0-beta.8.2
v0.1.0-beta.9
Fixed in
0.1.0-beta.13.2
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v0.1.0-beta.8.1
pre
1 CVE
GHSA-32wx-4gxx-h48f
Jan 29, 2021
Users can edit the tags of any discussion
Medium
This advisory concerns a vulnerability which was patched and publicly released on October 5, 2020. ImpactThis vulnerability allowed any registered user to edit the tags of any discussion for which they have READ access using the REST API. Users were able to remove any existing tag, and add any tag in which they are allowed to create discussions. The chosen tags still had to match the configured Tags minimums and maximums. By moving the discussion to new tags, users were able to go around permissions applied to restricted tags. Depending on the setup, this can include publicly exposing content that was only visible to certain groups, or gain the ability to interact with content where such interaction was limited. The full impact varies depending on the configuration of permissions and restricted tags, and which community extensions are being used. All tag-scoped permissions offered by extensions are impacted by this ability to go around them. Forums that don't use restricted tags and don't use any extension that relies on tags for access control should not see any security impact. An update is still required to stop users from being able to change any discussion's tags. Forums that don't use the Tags extension are unaffected. PatchesThe fix will be available in version v0.1.0-beta.14 with Flarum beta 14. The fix has already been back-ported to Flarum beta 13 as version v0.1.0-beta.13.2 of the Tags extension. WorkaroundsVersion v0.1.0-beta.13.2 of the Tags extension allows existing Flarum beta 13 forums to fix the issue without the need to update to beta 14. Forums that have not yet updated to Flarum beta 13 are encouraged to update as soon as possible. ReferencesFor more informationIf you have any questions or comments about this advisory, please start a new discussion on our support forum. If you discover a security vulnerability within Flarum, please send an e-mail to security@flarum.org. All security vulnerabilities will be promptly addressed. More details can be found in our security policy. Affected versions
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.13.1
v0.1.0-beta.3
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.8
v0.1.0-beta.8.1
+ 2 more Show less
v0.1.0-beta.8.2
v0.1.0-beta.9
Fixed in
0.1.0-beta.13.2
References
Updated Dec 02, 2024 · Source: OSV.dev |