CVE-2022-21642
Summary
| CVE | CVE-2022-21642 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-01-05 19:15:00 UTC |
| Updated | 2022-01-12 20:17:00 UTC |
| Description | Discourse is an open source platform for community discussion. In affected versions when composing a message from topic the composer user suggestions reveals whisper participants. The issue has been patched in stable version 2.7.13 and beta version 2.8.0.beta11. There is no workaround for this issue and users are advised to upgrade. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Discourse | Discourse | All | All | All | All |
| Application | Discourse | Discourse | 2.8.0 | beta1 | All | All |
| Application | Discourse | Discourse | 2.8.0 | beta10 | All | All |
| Application | Discourse | Discourse | 2.8.0 | beta2 | All | All |
| Application | Discourse | Discourse | 2.8.0 | beta3 | All | All |
| Application | Discourse | Discourse | 2.8.0 | beta4 | All | All |
| Application | Discourse | Discourse | 2.8.0 | beta5 | All | All |
| Application | Discourse | Discourse | 2.8.0 | beta6 | All | All |
| Application | Discourse | Discourse | 2.8.0 | beta7 | All | All |
| Application | Discourse | Discourse | 2.8.0 | beta8 | All | All |
| Application | Discourse | Discourse | 2.8.0 | beta9 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SECURITY: only show user suggestions with regular post (#15436) · discourse/discourse@702685b · GitHub | MISC | github.com | |
| Composing a message from topic reveals whisper participants · Advisory · discourse/discourse · GitHub | CONFIRM | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.