CVE-2021-43792

    Dashboard / Vulnerabilities / CVE-2021-43792

    CVE-2021-43792

    Published: 1 Dec 2021Last Modified: 9 Jul 2026

    Summary:

    Details: Discourse is an open source discussion platform. In affected versions a vulnerability affects users of tag groups who use the "Tags are visible only to the following groups" feature. A tag group may only allow a certain group (e.g. staff) to view certain tags. Users who were tracking or watching the tags via /preferences/tags, then have their staff status revoked will still see notifications related to the tag, but will not see the tag on each topic. This issue has been patched in stable version 2.7.11. Users are advised to upgrade as soon as possible.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Affected versions

    2.8.0-beta1
    2.8.0-beta2
    2.8.0-beta3
    2.8.0-beta4
    2.8.0-beta5
    2.8.0-beta6
    2.8.0-beta7

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2021-43792 | CVE-DB