PT-2022-16925 · Discourse · Discourse

·

CVE-2022-24850

·

Published

2022-04-14

·

Updated

2024-03-06

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Discourse versions prior to the latest stable, beta and tests-passed versions
Description Discourse is an open source platform for community discussion. A category's group permissions settings can be viewed by anyone that has access to the category. As a result, a normal user is able to see whether a group has read/write permissions in the category even though the information should only be available to the users that can manage a category.
Recommendations Update to the latest stable, beta or tests-passed version of Discourse to resolve the issue. As a temporary workaround, consider restricting access to category settings for non-managing users until a patch is applied. Restrict access to the group permissions settings to minimize the risk of exploitation.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2022-24850
CVE-2022-24850
GHSA-34XR-FF4W-MCPF

Affected Products

Discourse