Medium severity5.3NVD Advisory· Published Nov 2, 2022· Updated Jun 17, 2026
CVE-2022-39378
CVE-2022-39378
Description
Discourse is a platform for community discussion. Under certain conditions, a user badge may have been awarded based on a user's activity in a topic with restricted access. Before this vulnerability was disclosed, the topic title of the topic associated with the user badge may be viewed by any user. If there are sensitive information in the topic title, it will therefore have been exposed. This issue is patched in the latest stable, beta and tests-passed versions of Discourse. There are currently no known workarounds available.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
13cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*+ 11 more
- cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*range: <2.8.9
- cpe:2.3:a:discourse:discourse:2.9.0:beta1:*:*:*:*:*:*
- cpe:2.3:a:discourse:discourse:2.9.0:beta2:*:*:*:*:*:*
- cpe:2.3:a:discourse:discourse:2.9.0:beta3:*:*:*:*:*:*
- cpe:2.3:a:discourse:discourse:2.9.0:beta4:*:*:*:*:*:*
- cpe:2.3:a:discourse:discourse:2.9.0:beta5:*:*:*:*:*:*
- cpe:2.3:a:discourse:discourse:2.9.0:beta6:*:*:*:*:*:*
- cpe:2.3:a:discourse:discourse:2.9.0:beta7:*:*:*:*:*:*
- cpe:2.3:a:discourse:discourse:2.9.0:beta8:*:*:*:*:*:*
- cpe:2.3:a:discourse:discourse:2.9.0:beta9:*:*:*:*:*:*
- (no CPE)
- (no CPE)range: <= 2.8.9
Patches
Vulnerability mechanics
References
1- github.com/discourse/discourse/security/advisories/GHSA-2gvq-27h6-4h5fnvdThird Party Advisory
News mentions
0No linked articles in our index yet.