PT-2022-15030 · Discourse · Discourse

Lowjomaxropublished

·

Published

2022-01-13

·

Updated

2024-03-06

·

CVE-2022-21678

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Discourse versions prior to 2.8.0.beta11 in the tests-passed branch Discourse versions prior to 2.8.0.beta11 in the beta branch Discourse versions prior to 2.7.13 in the stable branch
Description The bios of users who made their profiles private were still visible in the tags on their users' pages.
Recommendations For versions prior to 2.8.0.beta11 in the tests-passed branch, update to version 2.8.0.beta11. For versions prior to 2.8.0.beta11 in the beta branch, update to version 2.8.0.beta11. For versions prior to 2.7.13 in the stable branch, update to version 2.7.13.

Exploit

Fix

Incorrect Authorization

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2022-21678
CVE-2022-21678
GHSA-JWWW-46GV-564M

Affected Products

Discourse