Incorrect Authorization Affecting fof/byobu package, versions >=0.3.0-beta.2, <1.1.7
Snyk CVSS
Attack Complexity
Low
User Interaction
Required
Threat Intelligence
Exploit Maturity
Proof of concept
EPSS
0.05% (18th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PHP-FOFBYOBU-2964942
- published 2 Aug 2022
- disclosed 2 Aug 2022
- credit Rafał Całka
Introduced: 2 Aug 2022
CVE-2022-35921 Open this link in a new tabHow to fix?
Upgrade fof/byobu
to version 1.1.7 or higher.
Overview
fof/byobu is a well integrated, advanced private discussions plugin for your Flarum forum
Affected versions of this package are vulnerable to Incorrect Authorization due to the user preference to prevent private discussions not being respected, which allows creating a private discussion with a user who disabled them.
Note:
Admins and others with appropriate permissions can always bypass this preference, regardless of version.