Medium severity4.3NVD Advisory· Published Nov 29, 2022· Updated Jun 17, 2026
CVE-2022-46150
CVE-2022-46150
Description
Discourse is an open-source discussion platform. Prior to version 2.8.13 of the stable branch and version 2.9.0.beta14 of the beta and tests-passed branches, unauthorized users may learn of the existence of hidden tags and that they have been applied to topics that they have access to. This issue is patched in version 2.8.13 of the stable branch and version 2.9.0.beta14 of the beta and tests-passed branches. As a workaround, use the disable_email site setting to disable all emails to non-staff users.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
16cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*+ 14 more
- cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*range: <2.8.13
- cpe:2.3:a:discourse:discourse:2.9.0:beta10:*:*:*:*:*:*
- cpe:2.3:a:discourse:discourse:2.9.0:beta11:*:*:*:*:*:*
- cpe:2.3:a:discourse:discourse:2.9.0:beta12:*:*:*:*:*:*
- cpe:2.3:a:discourse:discourse:2.9.0:beta13:*:*:*:*:*:*
- cpe:2.3:a:discourse:discourse:2.9.0:beta1:*:*:*:*:*:*
- cpe:2.3:a:discourse:discourse:2.9.0:beta2:*:*:*:*:*:*
- cpe:2.3:a:discourse:discourse:2.9.0:beta3:*:*:*:*:*:*
- cpe:2.3:a:discourse:discourse:2.9.0:beta4:*:*:*:*:*:*
- cpe:2.3:a:discourse:discourse:2.9.0:beta5:*:*:*:*:*:*
- cpe:2.3:a:discourse:discourse:2.9.0:beta6:*:*:*:*:*:*
- cpe:2.3:a:discourse:discourse:2.9.0:beta7:*:*:*:*:*:*
- cpe:2.3:a:discourse:discourse:2.9.0:beta8:*:*:*:*:*:*
- (no CPE)range: <2.8.13, <2.9.0.beta14
- (no CPE)range: < 2.8.13
Patches
Vulnerability mechanics
References
2- github.com/discourse/discourse/commit/84c83e8d4a1907f8a2972f0ab44b6402aa910c3bnvdPatchThird Party Advisory
- github.com/discourse/discourse/security/advisories/GHSA-rqvq-94h8-p5wvnvdThird Party Advisory
News mentions
0No linked articles in our index yet.