Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 3.0.0.beta16 on the `beta` and `tests-passed` branches, the number of times a user posted in an arbitrary topic is exposed to unauthorized users through the `/u/username.json` endpoint. The issue is patched in version 2.8.14 and 3.0.0.beta16. There is no known workaround.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-26615 Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 3.0.0.beta16 on the `beta` and `tests-passed` branches, the number of times a user posted in an arbitrary topic is exposed to unauthorized users through the `/u/username.json` endpoint. The issue is patched in version 2.8.14 and 3.0.0.beta16. There is no known workaround.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 10 Mar 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-03-10T21:31:52.286Z

Reserved: 2022-12-29T03:00:40.877Z

Link: CVE-2023-22453

cve-icon Vulnrichment

Updated: 2024-08-02T10:13:48.398Z

cve-icon NVD

Status : Modified

Published: 2023-01-05T20:15:18.743

Modified: 2024-11-21T07:44:50.127

Link: CVE-2023-22453

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.