Impact
Event invitees created in topics in private categories or PMs (private messages) can be retrieved by anyone, even if they're not logged in.
Patches
This problem is resolved in the latest version of the discourse-calendar plugin
Workarounds
No real workaround.
Putting the site behind login_required
will disallow this endpoint to be used by anonymous users, but logged in users can still get the list of invitees in the private topics.
Impact
Event invitees created in topics in private categories or PMs (private messages) can be retrieved by anyone, even if they're not logged in.
Patches
This problem is resolved in the latest version of the discourse-calendar plugin
Workarounds
No real workaround.
Putting the site behind
login_required
will disallow this endpoint to be used by anonymous users, but logged in users can still get the list of invitees in the private topics.