Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, information about restricted-visibility topic tags could be obtained by unauthorized users. The issue is patched in version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches.
Attack Vector Network
Attack Complexity Low
Privileges Required Low
Scope Unchanged
Confidentiality Impact Low
Integrity Impact None
Availability Impact None
User Interaction None
No CVSS v3.0
No CVSS v2
Vendors | Products |
---|---|
Discourse |
|
Configuration 1 [-]
|
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: GitHub_M
Published: 2023-07-28T15:27:19.780Z
Updated: 2023-07-28T15:27:19.780Z
Reserved: 2023-07-24T16:19:28.363Z
Link: CVE-2023-38685
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-07-28T16:15:12.613
Modified: 2023-08-03T17:35:33.533
Link: CVE-2023-38685
JSON object: View
Redhat Information
No data.