Unrated severityNVD Advisory· Published Jan 13, 2022· Updated Apr 23, 2025
User's bio visible even if profile is restricted in Discourse
CVE-2022-21678
Description
Discourse is an open source discussion platform. Prior to version 2.8.0.beta11 in the tests-passed branch, version 2.8.0.beta11 in the beta branch, and version 2.7.13 in the stable branch, the bios of users who made their profiles private were still visible in the ` tags on their users' pages. The problem is patched in tests-passed version 2.8.0.beta11, beta version 2.8.0.beta11, and stable` version 2.7.13 of Discourse.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3< 2.7.13 (stable), < 2.8.0.beta11 (beta, tests-passed)+ 1 more
- (no CPE)range: < 2.7.13 (stable), < 2.8.0.beta11 (beta, tests-passed)
- (no CPE)range: < 2.7.13
Patches
Vulnerability mechanics
References
3- github.com/discourse/discourse/commit/5e2e178fcfb490c37b9f8bb9f737185441b1d6demitrex_refsource_MISC
- github.com/discourse/discourse/commit/c0bb775f3f35b1b0d04a5b2a984f57c3e39f9e6cmitrex_refsource_MISC
- github.com/discourse/discourse/security/advisories/GHSA-jwww-46gv-564mmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.