CVE-2022-39378: Displaying user badges can leak topic titles to users that have no access to the topic
Discourse is a platform for community discussion. Under certain conditions, a user badge may have been awarded based on a user's activity in a topic with restricted access. Before this vulnerability was disclosed, the topic title of the topic associated with the user badge may be viewed by any user. If there are sensitive information in the topic title, it will therefore have been exposed. This issue is patched in the latest stable, beta and tests-passed versions of Discourse. There are currently no known workarounds available.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-39378?
CVE-2022-39378 is classified as a moderate severity vulnerability.
How do I fix CVE-2022-39378?
To fix CVE-2022-39378, users should upgrade to Discourse version 2.9.0 or later.
Which versions of Discourse are affected by CVE-2022-39378?
CVE-2022-39378 affects Discourse versions before 2.8.9 and all beta versions of 2.9.0.
What type of vulnerability is CVE-2022-39378?
CVE-2022-39378 is a vulnerability related to improper credential disclosure associated with user badges.
Can CVE-2022-39378 be exploited remotely?
Yes, CVE-2022-39378 can be exploited remotely under specific conditions.