CVE-2024-36122

LOW

Discourse <3.2.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta4 on the `beta` and `tests-passed` branches, moderators using the review queue to review users may see a users email address even when the Allow moderators to view email addresses setting is disabled. This issue is patched in version 3.2.3 on the `stable` branch and version 3.3.0.beta4 on the `beta` and `tests-passed` branches. As possible workarounds, either prevent moderators from accessing the review queue or disable the approve suspect users site setting and the must approve users site setting to prevent users from being added to the review queue.

Scores

CVSS v3 2.4
EPSS 0.0014
EPSS Percentile 33.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (3)
discourse/discourse 3.3.0 beta1 (3 CPE variants)
discourse/discourse < 3.2.3
discourse/discourse < 3.3.0
Published Jul 03, 2024
Tracked Since Feb 18, 2026