5.3
CVE-2026-45780
- EPSS 0.36%
- Veröffentlicht 09.07.2026 22:08:52
- Zuletzt bearbeitet 14.07.2026 20:43:40
- CVE-Watchlists
- Unerledigt
Discourse: Private event sample invitees are serialized to non-invited event viewers
Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, EventSerializer could expose invited group names, sample invitees, and attendance statistics to users who could view the topic but were not entitled to view the private event invitee list. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.36% | 0.287 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
| security-advisories@github.com | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
https://github.com/discourse/discourse/releases/tag/v2026.1.5
https://github.com/discourse/discourse/releases/tag/v2026.4.2
https://github.com/discourse/discourse/releases/tag/v2026.5.1
https://github.com/discourse/discourse/releases/tag/v2026.6.0
https://github.com/discourse/discourse/security/advisories/GHSA-22v7-6wgj-g9f7
https://github.com/discourse/discourse/commit/37969503f20369eb1712b7b88daedcfb4f63f5f1
https://github.com/discourse/discourse/commit/4d46638041b5f3d1e1f7f6f6f19c1df3bd65a586
https://github.com/discourse/discourse/commit/6457ab71f36a2d1440fe96af0a2593897844b023
https://github.com/discourse/discourse/commit/7deb4b6963442569357b41e61febe37594e5e730