5.3

CVE-2026-45780

Discourse: Private event sample invitees are serialized to non-invited event viewers

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, EventSerializer could expose invited group names, sample invitees, and attendance statistics to users who could view the topic but were not entitled to view the private event invitee list. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DiscourseDiscourse Version >= 2026.1.0 < 2026.1.5
DiscourseDiscourse Version >= 2026.4.0 < 2026.4.2
DiscourseDiscourse Version >= 2026.5.0 < 2026.5.1
DiscourseDiscourse Version2026.6.0 SwEditionlatest
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.36% 0.287
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
security-advisories@github.com 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

https://github.com/discourse/discourse/releases/tag/v2026.1.5
Release Notes
https://github.com/discourse/discourse/releases/tag/v2026.4.2
Release Notes
https://github.com/discourse/discourse/releases/tag/v2026.5.1
Release Notes
https://github.com/discourse/discourse/releases/tag/v2026.6.0
Release Notes
https://github.com/discourse/discourse/security/advisories/GHSA-22v7-6wgj-g9f7
Vendor Advisory
https://github.com/discourse/discourse/commit/37969503f20369eb1712b7b88daedcfb4f63f5f1
Patch
https://github.com/discourse/discourse/commit/4d46638041b5f3d1e1f7f6f6f19c1df3bd65a586
Patch
https://github.com/discourse/discourse/commit/6457ab71f36a2d1440fe96af0a2593897844b023
Patch
https://github.com/discourse/discourse/commit/7deb4b6963442569357b41e61febe37594e5e730
Patch