ثغرة Discourse-patreon؟

Joplin just posted that they had a vulnerability and user list was leaked.

Is there any more information about what happened?

إعجاب واحد (1)

Our security advisory for this is here:

3 إعجابات

Thank you I looked quite a bit but couldn’t find anything

إعجاب واحد (1)

I looked at the discourse GitHub but didn’t occur to me to check the plugin pages. Is there a best way to look for vulnerability across the board (discourse+plugins)? Whether an RSS feed or status page or?

إعجابَين (2)