Discourse

Discourse

188 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.19%
  • Veröffentlicht 14.04.2022 22:15:08
  • Zuletzt bearbeitet 21.11.2024 06:51:14

Discourse is an open source platform for community discussion. A category's group permissions settings can be viewed by anyone that has access to the category. As a result, a normal user is able to see whether a group has read/write permissions in th...

  • EPSS 0.38%
  • Veröffentlicht 14.04.2022 22:15:07
  • Zuletzt bearbeitet 21.11.2024 06:51:10

Discourse is an open source platform for community discussion. In affected versions an attacker can poison the cache for anonymous (i.e. not logged in) users, such that the users are shown the crawler view of the site instead of the HTML page. This c...

  • EPSS 0.19%
  • Veröffentlicht 11.04.2022 20:15:20
  • Zuletzt bearbeitet 21.11.2024 06:51:08

Discourse is an open source platform for community discussion. In stable versions prior to 2.8.3 and beta versions prior 2.9.0.beta4 erroneously expose groups. When a group with restricted visibility has been used to set the permissions of a category...

  • EPSS 0.39%
  • Veröffentlicht 24.03.2022 21:15:13
  • Zuletzt bearbeitet 21.11.2024 06:51:05

Discourse is an open source discussion platform. Versions 2.8.2 and prior in the `stable` branch, 2.9.0.beta3 and prior in the `beta` branch, and 2.9.0.beta3 and prior in the `tests-passed` branch are vulnerable to a data leak. Users can request an e...

  • EPSS 0.54%
  • Veröffentlicht 15.02.2022 21:15:07
  • Zuletzt bearbeitet 21.11.2024 06:48:59

Discourse is an open source discussion platform. In versions prior to 2.8.1 in the `stable` branch, 2.9.0.beta2 in the `beta` branch, and 2.9.0.beta2 in the `tests-passed` branch, users can trigger a Denial of Service attack by posting a streaming UR...

  • EPSS 0.36%
  • Veröffentlicht 14.01.2022 17:15:13
  • Zuletzt bearbeitet 21.11.2024 06:45:12

Discourse is an open source discussion platform. Discourse groups can be configured with varying visibility levels for the group as well as the group members. By default, a newly created group has its visibility set to public and the group's members ...

  • EPSS 0.13%
  • Veröffentlicht 13.01.2022 21:15:08
  • Zuletzt bearbeitet 21.11.2024 06:45:13

Discourse is an open source discussion platform. Versions prior to 2.7.13 in `stable`, 2.8.0.beta11 in `beta`, and 2.8.0.beta11 in `tests-passed` allow some users to log in to a community before they should be able to do so. A user invited via email ...

  • EPSS 0.31%
  • Veröffentlicht 13.01.2022 18:15:08
  • Zuletzt bearbeitet 21.11.2024 06:45:12

Discourse is an open source discussion platform. Prior to version 2.8.0.beta11 in the `tests-passed` branch, version 2.8.0.beta11 in the `beta` branch, and version 2.7.13 in the `stable` branch, the bios of users who made their profiles private were ...

  • EPSS 0.25%
  • Veröffentlicht 05.01.2022 19:15:09
  • Zuletzt bearbeitet 21.11.2024 06:45:08

Discourse is an open source platform for community discussion. In affected versions when composing a message from topic the composer user suggestions reveals whisper participants. The issue has been patched in stable version 2.7.13 and beta version 2...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 04.01.2022 20:15:07
  • Zuletzt bearbeitet 21.11.2024 06:29:55

Discourse is an open source platform for community discussion. In affected versions admins users can trigger a Denial of Service attack via the `/message-bus/_diagnostics` path. The impact of this vulnerability is greater on multisite Discourse insta...