PT-2023-19081 · Discourse · Discourse

Pmusaraj

·

Published

2023-01-27

·

Updated

2024-03-06

·

CVE-2023-23620

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Discourse versions prior to 3.0.1 on the stable branch Discourse versions prior to 3.1.0.beta2 on the beta and tests-passed branches
Description Discourse is an open-source discussion platform. The contents of latest/top routes for restricted tags can be accessed by unauthorized users. This issue is patched in version 3.0.1 on the stable branch and 3.1.0.beta2 on the beta and tests-passed branches.
Recommendations For Discourse versions prior to 3.0.1 on the stable branch, update to version 3.0.1 or later. For Discourse versions prior to 3.1.0.beta2 on the beta and tests-passed branches, update to version 3.1.0.beta2 or later.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2023-23620
CVE-2023-23620
GHSA-HVJ9-G84X-5PRX

Affected Products

Discourse