CVE-2022-46150

Discourse is an open-source discussion platform. Prior to version 2.8.13 of the `stable` branch and version 2.9.0.beta14 of the `beta` and `tests-passed` branches, unauthorized users may learn of the existence of hidden tags and that they have been applied to topics that they have access to. This issue is patched in version 2.8.13 of the `stable` branch and version 2.9.0.beta14 of the `beta` and `tests-passed` branches. As a workaround, use the `disable_email` site setting to disable all emails to non-staff users.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
GitHub_MCNA
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 25%
VendorProductVersion
discoursediscourse
𝑥
< 2.8.13
discoursediscourse
2.9.0:beta1
discoursediscourse
2.9.0:beta10
discoursediscourse
2.9.0:beta11
discoursediscourse
2.9.0:beta12
discoursediscourse
2.9.0:beta13
discoursediscourse
2.9.0:beta2
discoursediscourse
2.9.0:beta3
discoursediscourse
2.9.0:beta4
discoursediscourse
2.9.0:beta5
discoursediscourse
2.9.0:beta6
discoursediscourse
2.9.0:beta7
discoursediscourse
2.9.0:beta8
𝑥
= Vulnerable software versions