← Back

CVE-2023-23624

nvd nist
Published: Jan 28, 2023Modified: Nov 21, 2024

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and version 3.1.0.beta2 on the `beta` and `tests-passed` branches, someone can use the `exclude_tag param` to filter out topics and deduce which ones were using a specific hidden tag. This affects any Discourse site using hidden tags in public categories. This issue is patched in version 3.0.1 on the `stable` branch and version 3.1.0.beta2 on the `beta` and `tests-passed` branches. As a workaround, secure any categories that are using hidden tags, change any existing hidden tags to not include private data, or remove any hidden tags currently in use.

Affected (208)

Products: Discourse: Discourse
1 product
Discourse
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 3.0.1
Configuration B
207 vulnerable
Vulnerable SoftwareAffected Versions
Discourse
Version 1.1.0 beta1
Version 1.1.0 beta2
Version 1.1.0 beta3
Version 1.1.0 beta4
Version 1.1.0 beta5
Version 1.1.0 beta6
Version 1.1.0 beta6b
Version 1.1.0 beta7
Version 1.1.0 beta8
Version 1.2.0 beta1
Version 1.2.0 beta2
Version 1.2.0 beta3
Version 1.2.0 beta4
Version 1.2.0 beta5
Version 1.2.0 beta6
Version 1.2.0 beta7
Version 1.2.0 beta8
Version 1.2.0 beta9
Version 1.3.0 beta10
Version 1.3.0 beta11
Version 1.3.0 beta1
Version 1.3.0 beta2
Version 1.3.0 beta3
Version 1.3.0 beta4
Version 1.3.0 beta5
Version 1.3.0 beta6
Version 1.3.0 beta7
Version 1.3.0 beta8
Version 1.3.0 beta9
Version 1.4.0 beta10
Version 1.4.0 beta11
Version 1.4.0 beta12
Version 1.4.0 beta1
Version 1.4.0 beta2
Version 1.4.0 beta3
Version 1.4.0 beta4
Version 1.4.0 beta5
Version 1.4.0 beta6
Version 1.4.0 beta7
Version 1.4.0 beta8
Version 1.4.0 beta9
Version 1.5.0 beta10
Version 1.5.0 beta11
Version 1.5.0 beta12
Version 1.5.0 beta13
Version 1.5.0 beta13b
Version 1.5.0 beta14
Version 1.5.0 beta1
Version 1.5.0 beta2
Version 1.5.0 beta3
Version 1.5.0 beta4
Version 1.5.0 beta5
Version 1.5.0 beta6
Version 1.5.0 beta7
Version 1.5.0 beta8
Version 1.5.0 beta9
Version 1.6.0 beta10
Version 1.6.0 beta11
Version 1.6.0 beta12
Version 1.6.0 beta1
Version 1.6.0 beta2
Version 1.6.0 beta3
Version 1.6.0 beta4
Version 1.6.0 beta5
Version 1.6.0 beta6
Version 1.6.0 beta7
Version 1.6.0 beta8
Version 1.6.0 beta9
Version 1.7.0 beta10
Version 1.7.0 beta11
Version 1.7.0 beta1
Version 1.7.0 beta2
Version 1.7.0 beta3
Version 1.7.0 beta4
Version 1.7.0 beta5
Version 1.7.0 beta6
Version 1.7.0 beta7
Version 1.7.0 beta8
Version 1.7.0 beta9
Version 1.8.0 beta10
Version 1.8.0 beta11
Version 1.8.0 beta12
Version 1.8.0 beta13
Version 1.8.0 beta1
Version 1.8.0 beta2
Version 1.8.0 beta3
Version 1.8.0 beta4
Version 1.8.0 beta5
Version 1.8.0 beta6
Version 1.8.0 beta7
Version 1.8.0 beta8
Version 1.8.0 beta9
Version 1.9.0 beta10
Version 1.9.0 beta11
Version 1.9.0 beta12
Version 1.9.0 beta13
Version 1.9.0 beta14
Version 1.9.0 beta15
Version 1.9.0 beta16
Version 1.9.0 beta17
Version 1.9.0 beta1
Version 1.9.0 beta2
Version 1.9.0 beta3
Version 1.9.0 beta4
Version 1.9.0 beta5
Version 1.9.0 beta6
Version 1.9.0 beta7
Version 1.9.0 beta8
Version 1.9.0 beta9
Version 2.0.0 beta10
Version 2.0.0 beta1
Version 2.0.0 beta2
Version 2.0.0 beta3
Version 2.0.0 beta4
Version 2.0.0 beta5
Version 2.0.0 beta6
Version 2.0.0 beta7
Version 2.0.0 beta8
Version 2.0.0 beta9
Version 2.1.0 beta1
Version 2.1.0 beta2
Version 2.1.0 beta3
Version 2.1.0 beta4
Version 2.1.0 beta5
Version 2.1.0 beta6
Version 2.2.0 beta10
Version 2.2.0 beta1
Version 2.2.0 beta2
Version 2.2.0 beta3
Version 2.2.0 beta4
Version 2.2.0 beta5
Version 2.2.0 beta6
Version 2.2.0 beta7
Version 2.2.0 beta8
Version 2.2.0 beta9
Version 2.3.0 beta10
Version 2.3.0 beta11
Version 2.3.0 beta1
Version 2.3.0 beta2
Version 2.3.0 beta3
Version 2.3.0 beta4
Version 2.3.0 beta5
Version 2.3.0 beta6
Version 2.3.0 beta7
Version 2.3.0 beta8
Version 2.3.0 beta9
Version 2.4.0 beta10
Version 2.4.0 beta11
Version 2.4.0 beta1
Version 2.4.0 beta2
Version 2.4.0 beta3
Version 2.4.0 beta4
Version 2.4.0 beta5
Version 2.4.0 beta6
Version 2.4.0 beta7
Version 2.4.0 beta8
Version 2.4.0 beta9
Version 2.5.0 beta1
Version 2.5.0 beta2
Version 2.5.0 beta3
Version 2.5.0 beta4
Version 2.5.0 beta5
Version 2.5.0 beta6
Version 2.5.0 beta7
Version 2.6.0 beta1
Version 2.6.0 beta2
Version 2.6.0 beta3
Version 2.6.0 beta4
Version 2.6.0 beta5
Version 2.6.0 beta6
Version 2.7.0 beta1
Version 2.7.0 beta2
Version 2.7.0 beta3
Version 2.7.0 beta4
Version 2.7.0 beta5
Version 2.7.0 beta6
Version 2.7.0 beta7
Version 2.7.0 beta8
Version 2.7.0 beta9
Version 2.8.0 beta10
Version 2.8.0 beta11
Version 2.8.0 beta1
Version 2.8.0 beta2
Version 2.8.0 beta3
Version 2.8.0 beta4
Version 2.8.0 beta5
Version 2.8.0 beta6
Version 2.8.0 beta7
Version 2.8.0 beta8
Version 2.8.0 beta9
Version 2.9.0 beta10
Version 2.9.0 beta11
Version 2.9.0 beta12
Version 2.9.0 beta13
Version 2.9.0 beta14
Version 2.9.0 beta1
Version 2.9.0 beta2
Version 2.9.0 beta3
Version 2.9.0 beta4
Version 2.9.0 beta5
Version 2.9.0 beta6
Version 2.9.0 beta7
Version 2.9.0 beta8
Version 2.9.0 beta9
Version 3.0.0 beta15
Version 3.0.0 beta16
Version 3.1.0 beta1

References (6)

Source: security-advisories@github.com
Issue TrackingPatch
Source: security-advisories@github.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.