PT-2021-23938 · Discourse · Discourse
Samuel Grant
+1
·
Published
2021-12-01
·
Updated
2024-03-06
·
CVE-2021-43792
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Discourse versions prior to 2.7.11
Description:
A vulnerability affects users of tag groups who use the "Tags are visible only to the following groups" feature in Discourse, an open source discussion platform. This feature allows a tag group to restrict visibility of certain tags to specific groups, such as staff. However, if a user's group status is revoked, they may still receive notifications related to the tag, even though they can no longer view the tag on each topic.
Recommendations:
For versions prior to 2.7.11, upgrade to version 2.7.11 or later as soon as possible to resolve the issue. As a temporary workaround, consider restricting access to the
/preferences/tags endpoint for users who have had their staff status revoked, until the upgrade can be applied.Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Discourse