Discourse is an open source discussion platform. Prior to version 2.8.0.beta11 in the `tests-passed` branch, version 2.8.0.beta11 in the `beta` branch, and version 2.7.13 in the `stable` branch, the bios of users who made their profiles private were still visible in the `<meta>` tags on their users' pages. The problem is patched in `tests-passed` version 2.8.0.beta11, `beta` version 2.8.0.beta11, and `stable` version 2.7.13 of Discourse.
2022-01-13T18:15:08.233
2024-11-21T06:45:12.793
Modified
CVSSv3.1: 4.3 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:N/A:N
8.0
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | discourse | discourse | < 2.7.13 | Yes |
| Application | discourse | discourse | 2.8.0 | Yes |
| Application | discourse | discourse | 2.8.0 | Yes |
| Application | discourse | discourse | 2.8.0 | Yes |
| Application | discourse | discourse | 2.8.0 | Yes |
| Application | discourse | discourse | 2.8.0 | Yes |
| Application | discourse | discourse | 2.8.0 | Yes |
| Application | discourse | discourse | 2.8.0 | Yes |
| Application | discourse | discourse | 2.8.0 | Yes |
| Application | discourse | discourse | 2.8.0 | Yes |
| Application | discourse | discourse | 2.8.0 | Yes |