PT-2023-26549 · Discourse · Discourse

·

CVE-2023-38685

·

Published

2023-07-28

·

Updated

2024-03-06

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Discourse versions prior to 3.0.6 of the stable branch and version 3.1.0.beta7 of the beta and tests-passed branches.
Description Discourse is an open source discussion platform. Information about restricted-visibility topic tags could be obtained by unauthorized users.
Recommendations For versions prior to 3.0.6 of the stable branch, update to version 3.0.6 or later. For versions prior to 3.1.0.beta7 of the beta and tests-passed branches, update to version 3.1.0.beta7 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2023-38685
CVE-2023-38685
GHSA-WX6X-Q4GP-MGV5

Affected Products

Discourse