PT-2023-26549 · Discourse · Discourse

Jomaxro

·

Published

2023-07-28

·

Updated

2024-03-06

·

CVE-2023-38685

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Discourse versions prior to 3.0.6 of the stable branch and version 3.1.0.beta7 of the beta and tests-passed branches.
Description Discourse is an open source discussion platform. Information about restricted-visibility topic tags could be obtained by unauthorized users.
Recommendations For versions prior to 3.0.6 of the stable branch, update to version 3.0.6 or later. For versions prior to 3.1.0.beta7 of the beta and tests-passed branches, update to version 3.1.0.beta7 or later.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2023-38685
CVE-2023-38685
GHSA-WX6X-Q4GP-MGV5

Affected Products

Discourse