CVE-2022-39378

MEDIUM

Discourse < 2.8.9 - Unauthorized Exposure of Sensitive Topic Titles via User Badge

Title source: llm
STIX 2.1

Description

Discourse is a platform for community discussion. Under certain conditions, a user badge may have been awarded based on a user's activity in a topic with restricted access. Before this vulnerability was disclosed, the topic title of the topic associated with the user badge may be viewed by any user. If there are sensitive information in the topic title, it will therefore have been exposed. This issue is patched in the latest stable, beta and tests-passed versions of Discourse. There are currently no known workarounds available.

References (1)

Core 1

Scores

CVSS v3 5.3
EPSS 0.0029
EPSS Percentile 52.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (2)
discourse/discourse 2.9.0 beta1 (9 CPE variants)
discourse/discourse < 2.8.9
Published Nov 02, 2022
Tracked Since Feb 18, 2026