5.3
CVE-2026-59828
- EPSS 0.31%
- Veröffentlicht 09.07.2026 22:04:50
- Zuletzt bearbeitet 13.07.2026 15:22:59
- CVE-Watchlists
- Unerledigt
Discourse: Hidden post revisions leak through adjacent visible diffs
Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, post revisions that should be hidden from regular users could be leaked through visible diffs on adjacent revisions serialized by PostRevisionSerializer. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.31% | 0.233 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
https://github.com/discourse/discourse/releases/tag/v2026.1.5
https://github.com/discourse/discourse/releases/tag/v2026.4.2
https://github.com/discourse/discourse/releases/tag/v2026.5.1
https://github.com/discourse/discourse/releases/tag/v2026.6.0
https://github.com/discourse/discourse/security/advisories/GHSA-q456-4f8q-42vx
https://github.com/discourse/discourse/commit/1f26c1163ce87a2abbd1d01780ab1b5fb16e75f6
https://github.com/discourse/discourse/commit/8b773332b0f937dfcd894ed56d56fc5a81578d9d
https://github.com/discourse/discourse/commit/8d36da1b68c906592abde3f2e94d505cdf097435
https://github.com/discourse/discourse/commit/d58988d46bb1019bfa8b8330ae81a1a134e08511