PT-2023-26549 · Discourse · Discourse

Jomaxro

·

Publicado

2023-07-28

·

Atualizado

2024-03-06

·

CVE-2023-38685

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Discourse versions prior to 3.0.6 of the stable branch and version 3.1.0.beta7 of the beta and tests-passed branches.
Description Discourse is an open source discussion platform. Information about restricted-visibility topic tags could be obtained by unauthorized users.
Recommendations For versions prior to 3.0.6 of the stable branch, update to version 3.0.6 or later. For versions prior to 3.1.0.beta7 of the beta and tests-passed branches, update to version 3.1.0.beta7 or later.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BIT-DISCOURSE-2023-38685
CVE-2023-38685
GHSA-WX6X-Q4GP-MGV5

Produtos afetados

Discourse