Unrated severityNVD Advisory· Published Jan 13, 2022· Updated Apr 23, 2025
User's bio visible even if profile is restricted in Discourse
CVE-2022-21678
Description
Discourse is an open source discussion platform. Prior to version 2.8.0.beta11 in the tests-passed branch, version 2.8.0.beta11 in the beta branch, and version 2.7.13 in the stable branch, the bios of users who made their profiles private were still visible in the <meta> tags on their users' pages. The problem is patched in tests-passed version 2.8.0.beta11, beta version 2.8.0.beta11, and stable version 2.7.13 of Discourse.
Affected products
1- Range: < 2.7.13
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/discourse/discourse/commit/5e2e178fcfb490c37b9f8bb9f737185441b1d6demitrex_refsource_MISC
- github.com/discourse/discourse/commit/c0bb775f3f35b1b0d04a5b2a984f57c3e39f9e6cmitrex_refsource_MISC
- github.com/discourse/discourse/security/advisories/GHSA-jwww-46gv-564mmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.