Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-21642

Опубликовано: 05 янв. 2022
Источник: nvd
CVSS3: 4.3
CVSS2: 4
EPSS Низкий

Описание

Discourse is an open source platform for community discussion. In affected versions when composing a message from topic the composer user suggestions reveals whisper participants. The issue has been patched in stable version 2.7.13 and beta version 2.8.0.beta11. There is no workaround for this issue and users are advised to upgrade.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*
Версия до 2.7.13 (исключая)
cpe:2.3:a:discourse:discourse:2.8.0:beta1:*:*:*:*:*:*
cpe:2.3:a:discourse:discourse:2.8.0:beta10:*:*:*:*:*:*
cpe:2.3:a:discourse:discourse:2.8.0:beta2:*:*:*:*:*:*
cpe:2.3:a:discourse:discourse:2.8.0:beta3:*:*:*:*:*:*
cpe:2.3:a:discourse:discourse:2.8.0:beta4:*:*:*:*:*:*
cpe:2.3:a:discourse:discourse:2.8.0:beta5:*:*:*:*:*:*
cpe:2.3:a:discourse:discourse:2.8.0:beta6:*:*:*:*:*:*
cpe:2.3:a:discourse:discourse:2.8.0:beta7:*:*:*:*:*:*
cpe:2.3:a:discourse:discourse:2.8.0:beta8:*:*:*:*:*:*
cpe:2.3:a:discourse:discourse:2.8.0:beta9:*:*:*:*:*:*

EPSS

Процентиль: 48%
0.00248
Низкий

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-200
CWE-200

EPSS

Процентиль: 48%
0.00248
Низкий

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-200
CWE-200