GHSA-4j38-rw27-97gx
org.xwiki.contrib:discussions-server has Cross-Site Request Forgery (CSRF) issue that makes it possible to delete messages
Quick fix
GHSA-4j38-rw27-97gx — org.xwiki.contrib:discussions-server: upgrade to the fixed version with the command below.
# pom.xml: bump <version>2.0-rc-1</version> for org.xwiki.contrib:discussions-server Details
### Impact It's possible to forge a request to delete a message.
### Patches The problem has been patched in version 2.0-rc-1 of Discussion Extension.
### Workarounds There's no easy workaround except upgrading.
### References https://jira.xwiki.org/browse/DISCUSSION-22
### For more information If you have any questions or comments about this advisory: * Open an issue in [Jira XWiki](https://jira.xwiki.org) * Email us at [security mailing-list](mailto:security@xwiki.org)
Are you affected?
Enter the version of the package you're using.
Affected packages
0 Fixed in: 2.0-rc-1 # pom.xml: bump <version>2.0-rc-1</version> for org.xwiki.contrib:discussions-server