CVE-2022-46150: Discourse may allow exposure of hidden tags in the subject of notification emails
Discourse is an open-source discussion platform. Prior to version 2.8.13 of the stable branch and version 2.9.0.beta14 of the beta and tests-passed branches, unauthorized users may learn of the existence of hidden tags and that they have been applied to topics that they have access to. This issue is patched in version 2.8.13 of the stable branch and version 2.9.0.beta14 of the beta and tests-passed branches. As a workaround, use the disableemail site setting to disable all emails to non-staff users.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-46150?
The severity of CVE-2022-46150 is classified as moderate.
How do I fix CVE-2022-46150?
To fix CVE-2022-46150, upgrade to Discourse version 2.8.13 or version 2.9.0.beta14 or later.
What vulnerability does CVE-2022-46150 address?
CVE-2022-46150 addresses an issue where unauthorized users can learn about the existence of hidden tags applied to topics.
Which versions of Discourse are affected by CVE-2022-46150?
CVE-2022-46150 affects Discourse versions prior to 2.8.13 and various beta versions of 2.9.0.
Why is CVE-2022-46150 a concern for Discourse users?
CVE-2022-46150 is a concern as it allows unauthorized access to information that should be hidden, potentially leading to privacy issues.