Medium severity4.3NVD Advisory· Published Jan 13, 2022· Updated Jun 17, 2026
CVE-2022-21678
CVE-2022-21678
Description
Discourse is an open source discussion platform. Prior to version 2.8.0.beta11 in the tests-passed branch, version 2.8.0.beta11 in the beta branch, and version 2.7.13 in the stable branch, the bios of users who made their profiles private were still visible in the ` tags on their users' pages. The problem is patched in tests-passed version 2.8.0.beta11, beta version 2.8.0.beta11, and stable` version 2.7.13 of Discourse.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
14cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*+ 12 more
- cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*range: <2.7.13
- cpe:2.3:a:discourse:discourse:2.8.0:beta10:*:*:*:*:*:*
- cpe:2.3:a:discourse:discourse:2.8.0:beta1:*:*:*:*:*:*
- cpe:2.3:a:discourse:discourse:2.8.0:beta2:*:*:*:*:*:*
- cpe:2.3:a:discourse:discourse:2.8.0:beta3:*:*:*:*:*:*
- cpe:2.3:a:discourse:discourse:2.8.0:beta4:*:*:*:*:*:*
- cpe:2.3:a:discourse:discourse:2.8.0:beta5:*:*:*:*:*:*
- cpe:2.3:a:discourse:discourse:2.8.0:beta6:*:*:*:*:*:*
- cpe:2.3:a:discourse:discourse:2.8.0:beta7:*:*:*:*:*:*
- cpe:2.3:a:discourse:discourse:2.8.0:beta8:*:*:*:*:*:*
- cpe:2.3:a:discourse:discourse:2.8.0:beta9:*:*:*:*:*:*
- (no CPE)range: <2.8.0.beta11 (tests-passed), <2.8.0.beta11 (beta), <2.7.13 (stable)
- (no CPE)range: < 2.7.13
Patches
Vulnerability mechanics
References
3- github.com/discourse/discourse/commit/5e2e178fcfb490c37b9f8bb9f737185441b1d6denvdPatchThird Party Advisory
- github.com/discourse/discourse/commit/c0bb775f3f35b1b0d04a5b2a984f57c3e39f9e6cnvdPatchThird Party Advisory
- github.com/discourse/discourse/security/advisories/GHSA-jwww-46gv-564mnvdPatchThird Party Advisory
News mentions
0No linked articles in our index yet.