Skip to content

Possible flair abuse

Low
niklasf published GHSA-j8gh-p4wh-5j7h Dec 2, 2023

Package

No package listed

Affected versions

lichess-org/lifat@a4786d81834e640a74b10da2b011550e136f1ca8

Patched versions

lichess-org/lifat@440c644ba8d7a1f5bd7a3d05a64509f07ea87b16

Description

The recently introduced flairs included the official Lichess logo. Having the official logo next to their name may have given credibility and authority to people, facilitating social engineering.

The Lichess logo has now been removed from the set of flairs.

Severity

Low

CVE ID

No known CVE

Weaknesses

No CWEs