CVE-2022-21678: User's bio visible even if profile is restricted in Discourse
Discourse is an open source discussion platform. Prior to version 2.8.0.beta11 in the tests-passed branch, version 2.8.0.beta11 in the beta branch, and version 2.7.13 in the stable branch, the bios of users who made their profiles private were still visible in the <meta> tags on their users' pages. The problem is patched in tests-passed version 2.8.0.beta11, beta version 2.8.0.beta11, and stable version 2.7.13 of Discourse.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-21678?
CVE-2022-21678 has been classified as a moderate severity vulnerability.
How do I fix CVE-2022-21678?
To fix CVE-2022-21678, upgrade to Discourse version 2.8.0.beta11 or later in the beta branch, or version 2.7.13 in the stable branch.
What does CVE-2022-21678 affect?
CVE-2022-21678 affects the Discourse platform versions prior to 2.8.0.beta11 and 2.7.13 where user bios can be visible in meta tags.
Who is affected by CVE-2022-21678?
Users of the Discourse platform with private profiles are affected by CVE-2022-21678 as their bios could be exposed.
What is the impact of CVE-2022-21678 on user data privacy?
CVE-2022-21678 can lead to unauthorized access to user bios that were intended to be private, compromising user data privacy.