First published: Mon Oct 16 2023(Updated: )
Discourse is an open source platform for community discussion. User summaries are accessible for anonymous users even when `hide_user_profiles_from_public` is enabled. This problem has been patched in the 3.1.1 stable and 3.2.0.beta2 version of Discourse. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Credit: security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Discourse Discourse | <=3.1.1 | |
Discourse Discourse | =3.2.0-beta1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-44391 is a vulnerability in Discourse, an open source platform for community discussion. It allows anonymous users to access user summaries even when the 'hide_user_profiles_from_public' feature is enabled.
The severity of CVE-2023-44391 is medium, with a severity value of 5.3.
To fix CVE-2023-44391, users are advised to upgrade Discourse to the patched versions 3.1.1 stable or 3.2.0.beta2.
The affected software for CVE-2023-44391 is Discourse versions up to and including 3.1.1 stable and 3.2.0-beta1.
More information about CVE-2023-44391 can be found at the following reference: [GitHub Security Advisory](https://github.com/discourse/discourse/security/advisories/GHSA-7px5-fqcf-7mfr)