This repository was archived by the owner on Jul 15, 2025. It is now read-only.
Uninvited user is able to join and mark the attendance of the the private event
Package
Discourse
(Discourse)
Affected versions
>= 2201b254
Patched versions
> 2201b254
Impact
Uninvited users are able to gain access to private events by crafting a request to update their attendance.
Patches
This problem is resolved in the latest version of the discourse-calendar plugin
Workarounds
Existing access control is based on post visibility. Use that to limit access instead.