{"id":"CVE-2022-35921","aliases":["GHSA-6gjm-6wj6-4px5"],"url":"https://o3.security/vulnerability/CVE-2022-35921","summary":"User preference to prevent private discussions not respected in fof/byobu","details":"### Impact\nUsers electing to prevent others starting private discussions with themselves.\n\n> Please note that admins and others with appropriate permissions can always bypass this preference, as was the case before.\n\n### Patches\nUsers of Byobu should update the extension to version 1.1.7, where this has been patched. **This version is only supported on v1.2.0 and later of Flarum Core.**\n\nUsers of Byobu with Flarum 1.0 or 1.1 should upgrade to Flarum 1.2 or later, or evaluate the impact this issue has on your forum's users and choose to disable the extension if needed.\n\n### Workarounds\nThere are no workarounds for this issue.","published":"2022-08-01T21:50:10Z","modified":"2026-08-12T03:51:38.832688778Z","cvss":{"score":3.5,"severity":"LOW","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"},"epss":{"score":0.00503,"percentile":0.41403,"asOf":"2026-09-09"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"fof/byobu","fixedVersion":"1.1.7"}],"fix":{"url":"https://github.com/FriendsOfFlarum/byobu/commit/23dcf93a30f948d30c678a96681f7fdefeba5171","label":"FriendsOfFlarum/byobu@23dcf93"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/35xxx/CVE-2022-35921.json"},{"type":"ADVISORY","url":"https://github.com/FriendsOfFlarum/byobu/security/advisories/GHSA-6gjm-6wj6-4px5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-35921"},{"type":"FIX","url":"https://github.com/FriendsOfFlarum/byobu/commit/23dcf93a30f948d30c678a96681f7fdefeba5171"},{"type":"PACKAGE","url":"https://github.com/FriendsOfFlarum/byobu"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:38.832688778Z"}}