CVE-2021-37703: Information exposure in Discourse
Discourse is an open-source platform for community discussion. In Discourse before versions 2.7.8 and 2.8.0.beta5, a user's read state for a topic such as the last read post number and the notification level is exposed.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Discourseto a version that resolves this vulnerability.Fixed in 2.7.8 - Upgrade
Upgrade
Discourseto a version that resolves this vulnerability.Fixed in 2.8.0.beta5 - Compensating control
Ensure users cannot access another user's exposed read state (e.g., last read post number and notification level) by verifying authorization boundaries around topic read-state and notification data endpoints/pages after upgrading.
Event History
Frequently Asked Questions
What is the severity of CVE-2021-37703?
CVE-2021-37703 has a moderate severity due to exposure of a user's read state that could lead to information leakage.
How do I fix CVE-2021-37703?
To fix CVE-2021-37703, upgrade your Discourse installation to version 2.7.8 or 2.8.0.beta5 or later.
What systems are affected by CVE-2021-37703?
CVE-2021-37703 affects Discourse versions prior to 2.7.8 and the 2.8.0 beta versions before beta5.
What type of vulnerability is CVE-2021-37703?
CVE-2021-37703 is an information disclosure vulnerability related to topic read states.
Can I access the fixes for CVE-2021-37703 from Discourse?
Yes, the fixes for CVE-2021-37703 are available in the latest releases of Discourse.