First published: Thu Jan 13 2022(Updated: )
Discourse is an open source discussion platform. Prior to version 2.8.0.beta11 in the `tests-passed` branch, version 2.8.0.beta11 in the `beta` branch, and version 2.7.13 in the `stable` branch, the bios of users who made their profiles private were still visible in the `<meta>` tags on their users' pages. The problem is patched in `tests-passed` version 2.8.0.beta11, `beta` version 2.8.0.beta11, and `stable` version 2.7.13 of Discourse.
Credit: security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Discourse Discourse | <2.7.13 | |
Discourse Discourse | =2.8.0-beta1 | |
Discourse Discourse | =2.8.0-beta10 | |
Discourse Discourse | =2.8.0-beta2 | |
Discourse Discourse | =2.8.0-beta3 | |
Discourse Discourse | =2.8.0-beta4 | |
Discourse Discourse | =2.8.0-beta5 | |
Discourse Discourse | =2.8.0-beta6 | |
Discourse Discourse | =2.8.0-beta7 | |
Discourse Discourse | =2.8.0-beta8 | |
Discourse Discourse | =2.8.0-beta9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.