Exploit Report

Computer Security And Bug Information

CVE-2023-23624

CVECVE-2023-23624
CVE Title
Published Date2023-01-28T00:15Z
Modified Date2023-01-30T14:18Z
CWE TypeCWE-200
DescriptionDiscourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and version 3.1.0.beta2 on the `beta` and `tests-passed` branches, someone can use the `exclude_tag param` to filter out topics and deduce which ones were using a specific hidden tag. This affects any Discourse site using hidden tags in public categories. This issue is patched in version 3.0.1 on the `stable` branch and version 3.1.0.beta2 on the `beta` and `tests-passed` branches. As a workaround, secure any categories that are using hidden tags, change any existing hidden tags to not include private data, or remove any hidden tags currently in use.
References
By clicking these links you will leave this website. We do not endorse and will not be held accountable for any activity on external sites.
Reference URLhttps://github.com/discourse/discourse/pull/20006
Reference DescriptionMISC https://github.com/discourse/discourse/pull/20006
Reference URLhttps://github.com/discourse/discourse/security/advisories/GHSA-qgj5-g5vf-fm7q
Reference DescriptionMISC https://github.com/discourse/discourse/security/advisories/GHSA-qgj5-g5vf-fm7q
Reference URLhttps://github.com/discourse/discourse/commit/f55e0fe7910149c431861c18ce407d1be0d6091a
Reference DescriptionMISC https://github.com/discourse/discourse/commit/f55e0fe7910149c431861c18ce407d1be0d6091a
Sources NIST MITRE
Note
  • No CVSS data for this CVE

This site's data is aggregated programmatically and provided "as is" without any representations or warranties, express or implied. Exploit.report is not affiliated with the The MITRE Corporation, U.S. Department of Homeland Security (DHS), Cybersecurity and Infrastructure Security Agency (CISA), or US government in any way. CVE and the CVE logo are registered trademarks of The MITRE Corporation

© 2022 Exploit.Report | Data | Contact | Privacy Policy | Articles