Unrated severityNVD Advisory· Published Jan 5, 2023· Updated Mar 10, 2025
Discourse vulnerable to private topic leak via email#send_digest
CVE-2022-23546
Description
In version 2.9.0.beta14 of Discourse, an open-source discussion platform, maliciously embedded urls can leak an admin's digest of recent topics, possibly exposing private information. A patch is available for version 2.9.0.beta15. There are no known workarounds for this issue.
Affected products
1- Range: = 2.9.0.beta14
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/discourse/discourse/commit/cf862e736565c6fa905c12b5dbe63d0bd056efb8mitrex_refsource_MISC
- github.com/discourse/discourse/security/advisories/GHSA-q9jp-xv4g-328fmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.