6.3

CVE-2025-64528

Users are able to find users by name even when `enable_names` is off

Discourse is an open source discussion platform. Prior to versions 3.5.3, 2025.11.1, and 2025.12.0, an attacker who knows part of a username can find the user and their full name via UI or API, even when `enable_names` is disabled. Versions 3.5.3, 2025.11.1, and 2025.12.0 contain a fix.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DiscourseDiscourse Version < 3.5.3
DiscourseDiscourse Version2025.11.0 SwEditionstable
DiscourseDiscourse Version2025.12.0 SwEditionstable
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.24% 0.15
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
security-advisories@github.com 6.3 0 0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-202 Exposure of Sensitive Information Through Data Queries

When trying to keep information confidential, an attacker can often infer some of the information by using statistics.

https://github.com/discourse/discourse/commit/1cb45b8b287597085e3514596ffb1d9b41938f81
Patch
https://github.com/discourse/discourse/commit/6192f55629624925595dae14364fd86cac0f09df
Patch
https://github.com/discourse/discourse/commit/e936a523b5900a9d866d23ea3da904ba12bb0fb2
Patch
https://github.com/discourse/discourse/security/advisories/GHSA-c59w-jwx7-34v4
Third Party Advisory