CVE-2021-32788
Discourse is an open source discussion platform.
Does this matter?
Lower severity and a low EPSS score (0.89%). Track it; it rarely justifies an emergency change on its own.
Description
Discourse is an open source discussion platform. In versions prior to 2.7.7 there are two bugs which led to the post creator of a whisper post being revealed to non-staff users. 1: Staff users that creates a whisper post in a personal message is revealed to non-staff participants of the personal message even though the whisper post cannot be seen by them. 2: When a whisper post is before the last post in a post stream, deleting the last post will result in the creator of the whisper post to be revealed to non-staff users as the last poster of the topic.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.89% probability · 57th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-668
- Affected
- discourse/discourse
- Source
- security-advisories@github.com
References
- https://github.com/discourse/discourse/commit/680024f9071b7696e5a444a58791016c6dc1f1e5Patch, Third Party Advisory
- https://github.com/discourse/discourse/commit/dbdf61196d9e964e8823793d2e7f856595fea4d9Patch, Third Party Advisory
- https://github.com/discourse/discourse/security/advisories/GHSA-v6xg-q577-vc92Third Party Advisory
- https://github.com/discourse/discourse/commit/680024f9071b7696e5a444a58791016c6dc1f1e5Patch, Third Party Advisory
- https://github.com/discourse/discourse/commit/dbdf61196d9e964e8823793d2e7f856595fea4d9Patch, Third Party Advisory
- https://github.com/discourse/discourse/security/advisories/GHSA-v6xg-q577-vc92Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.