CVE-2022-24804 Information
Jun 07, 2022
cve
Description
Discourse is an open source platform for community discussion. In stable versions prior to 2.8.3 and beta versions prior 2.9.0.beta4 erroneously expose groups. When a group with restricted visibility has been used to set the permissions of a category the name of the group is leaked to any user that is able to see the category. To workaround the problem a site administrator can remove groups with restricted visibility from any category’s permissions setting.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Reference
https://github.com/discourse/discourse/security/advisories/GHSA-v4c9-6m9g-37ff https://github.com/discourse/discourse/commit/0f7b9878ff3207ce20970f0517604793920bb3d2
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
5.3
Share on: