icon

We found results for “

CVE-2022-31060

Date: June 14, 2022

Discourse is an open-source discussion platform. Prior to version 2.8.4 in the "stable" branch and version "2.9.0.beta5" in the "beta" and "tests-passed" branches, banner topic data is exposed on login-required sites. This issue is patched in version 2.8.4 in the "stable" branch and version "2.9.0.beta5" in the "beta" and "tests-passed" branches of Discourse. As a workaround, one may disable banners.

Language: Ruby

Severity Score

Severity Score

Weakness Type (CWE)

Exposure of Sensitive Information to an Unauthorized Actor

CWE-200

Insufficient Information

NVD-CWE-noinfo

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): LOW
Integrity (I): NONE
Availability (A): NONE

CVSS v2

Base Score:
Access Vector (AV): NETWORK
Access Complexity (AC): LOW
Authentication (AU): NONE
Confidentiality (C): PARTIAL
Integrity (I): NONE
Availability (A): NONE
Additional information:

Do you need more information?

Contact Us