VYPR
Medium severity5.3NVD Advisory· Published Nov 2, 2022· Updated Jun 17, 2026

CVE-2022-39378

CVE-2022-39378

Description

Discourse is a platform for community discussion. Under certain conditions, a user badge may have been awarded based on a user's activity in a topic with restricted access. Before this vulnerability was disclosed, the topic title of the topic associated with the user badge may be viewed by any user. If there are sensitive information in the topic title, it will therefore have been exposed. This issue is patched in the latest stable, beta and tests-passed versions of Discourse. There are currently no known workarounds available.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

13
  • cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*+ 11 more
    • cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*range: <2.8.9
    • cpe:2.3:a:discourse:discourse:2.9.0:beta1:*:*:*:*:*:*
    • cpe:2.3:a:discourse:discourse:2.9.0:beta2:*:*:*:*:*:*
    • cpe:2.3:a:discourse:discourse:2.9.0:beta3:*:*:*:*:*:*
    • cpe:2.3:a:discourse:discourse:2.9.0:beta4:*:*:*:*:*:*
    • cpe:2.3:a:discourse:discourse:2.9.0:beta5:*:*:*:*:*:*
    • cpe:2.3:a:discourse:discourse:2.9.0:beta6:*:*:*:*:*:*
    • cpe:2.3:a:discourse:discourse:2.9.0:beta7:*:*:*:*:*:*
    • cpe:2.3:a:discourse:discourse:2.9.0:beta8:*:*:*:*:*:*
    • cpe:2.3:a:discourse:discourse:2.9.0:beta9:*:*:*:*:*:*
    • (no CPE)
    • (no CPE)range: <= 2.8.9
  • osv-coords
    Range: < 2.8.9

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.