CVE-2021-32788

Discourse is an open source discussion platform. In versions prior to 2.7.7 there are two bugs which led to the post creator of a whisper post being revealed to non-staff users. 1: Staff users that creates a whisper post in a personal message is revealed to non-staff participants of the personal message even though the whisper post cannot be seen by them. 2: When a whisper post is before the last post in a post stream, deleting the last post will result in the creator of the whisper post to be revealed to non-staff users as the last poster of the topic.
Configurations

Configuration 1 (hide)

cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*

History

05 Aug 2021, 13:31

Type Values Removed Values Added
References (MISC) https://github.com/discourse/discourse/commit/dbdf61196d9e964e8823793d2e7f856595fea4d9 - (MISC) https://github.com/discourse/discourse/commit/dbdf61196d9e964e8823793d2e7f856595fea4d9 - Patch, Third Party Advisory
References (CONFIRM) https://github.com/discourse/discourse/security/advisories/GHSA-v6xg-q577-vc92 - (CONFIRM) https://github.com/discourse/discourse/security/advisories/GHSA-v6xg-q577-vc92 - Third Party Advisory
References (MISC) https://github.com/discourse/discourse/commit/680024f9071b7696e5a444a58791016c6dc1f1e5 - (MISC) https://github.com/discourse/discourse/commit/680024f9071b7696e5a444a58791016c6dc1f1e5 - Patch, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 4.0
v3 : 4.3
CPE cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*
CWE CWE-668

30 Jul 2021, 14:15

Type Values Removed Values Added
Summary Discourse is an open source discussion platform. In versions prior to 2.7.7 there are two bugs which led to the post creator of a whisper post being revealed to non-staff users. 1: Staff users that creates a whisper post in a personal message is revealed to non-staff participants of the personal message even though the whisper post cannot be seen by them. 2: When a whisper post is before the last post in a post stream, deleting the last post will result in the creator of the whisper post to be revealed to non-staff users as the last poster of the topic. Discourse is an open source discussion platform. In versions prior to 2.7.7 there are two bugs which led to the post creator of a whisper post being revealed to non-staff users. 1: Staff users that creates a whisper post in a personal message is revealed to non-staff participants of the personal message even though the whisper post cannot be seen by them. 2: When a whisper post is before the last post in a post stream, deleting the last post will result in the creator of the whisper post to be revealed to non-staff users as the last poster of the topic.

27 Jul 2021, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-07-27 22:15

Updated : 2023-12-10 13:55


NVD link : CVE-2021-32788

Mitre link : CVE-2021-32788

CVE.ORG link : CVE-2021-32788


JSON object : View

Products Affected

discourse

  • discourse
CWE
CWE-668

Exposure of Resource to Wrong Sphere