BIT-discourse-2021-32788

    Dashboard / Vulnerabilities / BIT-discourse-2021-32788

    BIT-discourse-2021-32788

    Published: 6 Mar 2024Last Modified: 8 Sept 2026

    Summary: Post creator of a whisper post can be revealed to non-staff users in Discourse

    Details: Discourse is an open source discussion platform. In versions prior to 2.7.7 there are two bugs which led to the post creator of a whisper post being revealed to non-staff users. 1: Staff users that creates a whisper post in a personal message is revealed to non-staff participants of the personal message even though the whisper post cannot be seen by them. 2: When a whisper post is before the last post in a post stream, deleting the last post will result in the creator of the whisper post to be revealed to non-staff users as the last poster of the topic.

    Affected packages

    Package

    Name: discourse

    Purl: pkg:bitnami/discourse

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -2.7.7

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    BIT-discourse-2021-32788 | CVE-DB