CVE-2022-21684
- EPSS 0.96%
- Veröffentlicht 13.01.2022 21:15:08
- Zuletzt bearbeitet 21.11.2024 06:45:13
Discourse is an open source discussion platform. Versions prior to 2.7.13 in `stable`, 2.8.0.beta11 in `beta`, and 2.8.0.beta11 in `tests-passed` allow some users to log in to a community before they should be able to do so. A user invited via email ...
CVE-2022-21678
- EPSS 0.91%
- Veröffentlicht 13.01.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:45:12
Discourse is an open source discussion platform. Prior to version 2.8.0.beta11 in the `tests-passed` branch, version 2.8.0.beta11 in the `beta` branch, and version 2.7.13 in the `stable` branch, the bios of users who made their profiles private were ...
CVE-2022-21642
- EPSS 0.73%
- Veröffentlicht 05.01.2022 19:15:09
- Zuletzt bearbeitet 21.11.2024 06:45:08
Discourse is an open source platform for community discussion. In affected versions when composing a message from topic the composer user suggestions reveals whisper participants. The issue has been patched in stable version 2.7.13 and beta version 2...
CVE-2021-43850
- EPSS 0.83%
- Veröffentlicht 04.01.2022 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:29:55
Discourse is an open source platform for community discussion. In affected versions admins users can trigger a Denial of Service attack via the `/message-bus/_diagnostics` path. The impact of this vulnerability is greater on multisite Discourse insta...
CVE-2021-43792
- EPSS 0.83%
- Veröffentlicht 01.12.2021 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:29:47
Discourse is an open source discussion platform. In affected versions a vulnerability affects users of tag groups who use the "Tags are visible only to the following groups" feature. A tag group may only allow a certain group (e.g. staff) to view cer...
- EPSS 0.76%
- Veröffentlicht 01.12.2021 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:29:48
Discourse is an open source discussion platform. In affected versions a vulnerability in the Polls feature allowed users to vote multiple times in a single-option poll. The problem is patched in the latest tests-passed, beta and stable versions of Di...
- EPSS 1.02%
- Veröffentlicht 01.12.2021 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:29:48
Discourse is an open source discussion platform. In affected versions an attacker can poison the cache for anonymous (i.e. not logged in) users, such that the users are shown a JSON blob instead of the HTML page. This can lead to a partial denial-of-...
CVE-2021-41271
- EPSS 0.94%
- Veröffentlicht 15.11.2021 22:15:06
- Zuletzt bearbeitet 21.11.2024 06:25:56
Discourse is a platform for community discussion. In affected versions a maliciously crafted request could cause an error response to be cached by intermediate proxies. This could cause a loss of confidentiality for some content. This issue is patche...
CVE-2021-41163
- EPSS 19.81%
- Veröffentlicht 20.10.2021 23:15:07
- Zuletzt bearbeitet 21.11.2024 06:25:38
Discourse is an open source platform for community discussion. In affected versions maliciously crafted requests could lead to remote code execution. This resulted from a lack of validation in subscribe_url values. This issue is patched in the latest...
CVE-2021-41095
- EPSS 0.57%
- Veröffentlicht 27.09.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:25:27
Discourse is an open source discussion platform. There is a cross-site scripting (XSS) vulnerability in versions 2.7.7 and earlier of the `stable` branch, versions 2.8.0.beta6 and earlier of the `beta` branch, and versions 2.8.0.beta6 and earlier of ...