PT-2021-23938 · Discourse · Discourse

·

CVE-2021-43792

·

Published

2021-12-01

·

Updated

2024-03-06

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Discourse versions prior to 2.7.11
Description: A vulnerability affects users of tag groups who use the "Tags are visible only to the following groups" feature in Discourse, an open source discussion platform. This feature allows a tag group to restrict visibility of certain tags to specific groups, such as staff. However, if a user's group status is revoked, they may still receive notifications related to the tag, even though they can no longer view the tag on each topic.
Recommendations: For versions prior to 2.7.11, upgrade to version 2.7.11 or later as soon as possible to resolve the issue. As a temporary workaround, consider restricting access to the /preferences/tags endpoint for users who have had their staff status revoked, until the upgrade can be applied.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2021-43792
CVE-2021-43792
GHSA-PQ2X-VQ37-8522

Affected Products

Discourse