CVE-2022-21678
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/01/2022
Last modified:
24/07/2023
Description
Discourse is an open source discussion platform. Prior to version 2.8.0.beta11 in the `tests-passed` branch, version 2.8.0.beta11 in the `beta` branch, and version 2.7.13 in the `stable` branch, the bios of users who made their profiles private were still visible in the `` tags on their users' pages. The problem is patched in `tests-passed` version 2.8.0.beta11, `beta` version 2.8.0.beta11, and `stable` version 2.7.13 of Discourse.
Impact
Base Score 3.x
4.30
Severity 3.x
MEDIUM
Base Score 2.0
4.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:* | 2.7.13 (excluding) | |
| cpe:2.3:a:discourse:discourse:2.8.0:beta1:*:*:*:*:*:* | ||
| cpe:2.3:a:discourse:discourse:2.8.0:beta10:*:*:*:*:*:* | ||
| cpe:2.3:a:discourse:discourse:2.8.0:beta2:*:*:*:*:*:* | ||
| cpe:2.3:a:discourse:discourse:2.8.0:beta3:*:*:*:*:*:* | ||
| cpe:2.3:a:discourse:discourse:2.8.0:beta4:*:*:*:*:*:* | ||
| cpe:2.3:a:discourse:discourse:2.8.0:beta5:*:*:*:*:*:* | ||
| cpe:2.3:a:discourse:discourse:2.8.0:beta6:*:*:*:*:*:* | ||
| cpe:2.3:a:discourse:discourse:2.8.0:beta7:*:*:*:*:*:* | ||
| cpe:2.3:a:discourse:discourse:2.8.0:beta8:*:*:*:*:*:* | ||
| cpe:2.3:a:discourse:discourse:2.8.0:beta9:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



