Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta4 on the `beta` and `tests-passed` branches, moderators using the review queue to review users may see a users email address even when the Allow moderators to view email addresses setting is disabled. This issue is patched in version 3.2.3 on the `stable` branch and version 3.3.0.beta4 on the `beta` and `tests-passed` branches. As possible workarounds, either prevent moderators from accessing the review queue or disable the approve suspect users site setting and the must approve users site setting to prevent users from being added to the review queue.
History

Wed, 18 Sep 2024 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Discourse
Discourse discourse
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:discourse:discourse:*:*:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:*:*:*:*:stable:*:*:*
cpe:2.3:a:discourse:discourse:3.3.0:beta1:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:3.3.0:beta2:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:3.3.0:beta3:*:*:beta:*:*:*
Vendors & Products Discourse
Discourse discourse

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-07-03T19:10:45.955Z

Updated: 2024-08-02T03:30:13.046Z

Reserved: 2024-05-20T21:07:48.189Z

Link: CVE-2024-36122

cve-icon Vulnrichment

Updated: 2024-07-05T14:23:35.259Z

cve-icon NVD

Status : Analyzed

Published: 2024-07-03T20:15:04.243

Modified: 2024-09-18T13:55:27.633

Link: CVE-2024-36122

cve-icon Redhat

No data.