Discourse

Discourse

280 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.04%
  • Veröffentlicht 14.06.2022 21:15:16
  • Zuletzt bearbeitet 21.11.2024 07:03:48

Discourse is an open-source discussion platform. Prior to version 2.8.4 in the `stable` branch and version `2.9.0.beta5` in the `beta` and `tests-passed` branches, banner topic data is exposed on login-required sites. This issue is patched in version...

  • EPSS 0.96%
  • Veröffentlicht 07.06.2022 15:15:09
  • Zuletzt bearbeitet 21.11.2024 07:03:44

Discourse is an open source platform for community discussion. Prior to version 2.8.4 on the `stable` branch and 2.9.0beta5 on the `beta` and `tests-passed` branches, inviting users on sites that use single sign-on could bypass the `must_approve_user...

  • EPSS 0.65%
  • Veröffentlicht 14.04.2022 22:15:08
  • Zuletzt bearbeitet 21.11.2024 06:51:14

Discourse is an open source platform for community discussion. A category's group permissions settings can be viewed by anyone that has access to the category. As a result, a normal user is able to see whether a group has read/write permissions in th...

  • EPSS 1%
  • Veröffentlicht 14.04.2022 22:15:07
  • Zuletzt bearbeitet 21.11.2024 06:51:10

Discourse is an open source platform for community discussion. In affected versions an attacker can poison the cache for anonymous (i.e. not logged in) users, such that the users are shown the crawler view of the site instead of the HTML page. This c...

  • EPSS 0.85%
  • Veröffentlicht 11.04.2022 20:15:20
  • Zuletzt bearbeitet 21.11.2024 06:51:08

Discourse is an open source platform for community discussion. In stable versions prior to 2.8.3 and beta versions prior 2.9.0.beta4 erroneously expose groups. When a group with restricted visibility has been used to set the permissions of a category...

  • EPSS 0.97%
  • Veröffentlicht 24.03.2022 21:15:13
  • Zuletzt bearbeitet 21.11.2024 06:51:05

Discourse is an open source discussion platform. Versions 2.8.2 and prior in the `stable` branch, 2.9.0.beta3 and prior in the `beta` branch, and 2.9.0.beta3 and prior in the `tests-passed` branch are vulnerable to a data leak. Users can request an e...

  • EPSS 1.16%
  • Veröffentlicht 15.02.2022 21:15:07
  • Zuletzt bearbeitet 21.11.2024 06:48:59

Discourse is an open source discussion platform. In versions prior to 2.8.1 in the `stable` branch, 2.9.0.beta2 in the `beta` branch, and 2.9.0.beta2 in the `tests-passed` branch, users can trigger a Denial of Service attack by posting a streaming UR...

  • EPSS 1.17%
  • Veröffentlicht 14.01.2022 17:15:13
  • Zuletzt bearbeitet 21.11.2024 06:45:12

Discourse is an open source discussion platform. Discourse groups can be configured with varying visibility levels for the group as well as the group members. By default, a newly created group has its visibility set to public and the group's members ...

  • EPSS 0.83%
  • Veröffentlicht 13.01.2022 21:15:08
  • Zuletzt bearbeitet 21.11.2024 06:45:13

Discourse is an open source discussion platform. Versions prior to 2.7.13 in `stable`, 2.8.0.beta11 in `beta`, and 2.8.0.beta11 in `tests-passed` allow some users to log in to a community before they should be able to do so. A user invited via email ...

  • EPSS 0.79%
  • Veröffentlicht 13.01.2022 18:15:08
  • Zuletzt bearbeitet 21.11.2024 06:45:12

Discourse is an open source discussion platform. Prior to version 2.8.0.beta11 in the `tests-passed` branch, version 2.8.0.beta11 in the `beta` branch, and version 2.7.13 in the `stable` branch, the bios of users who made their profiles private were ...