Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-49845

Опубликовано: 25 июн. 2025
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Discourse is an open-source discussion platform. The visibility of posts typed whisper is controlled via the whispers_allowed_groups site setting. Only users that belong to groups specified in the site setting are allowed to view posts typed whisper. However, it has been discovered that users of versions prior to 3.4.6 on the stable branch and prior to 3.5.0.beta8-dev on the tests-passed branch can continue to see their own whispers even after losing visibility of posts typed whisper. This issue is patched in versions 3.4.6 and 3.5.0.beta8-dev. No known workarounds are available.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:discourse:discourse:*:*:*:*:stable:*:*:*
Версия до 3.4.6 (исключая)

EPSS

Процентиль: 18%
0.00057
Низкий

7.5 High

CVSS3

Дефекты

CWE-200
NVD-CWE-noinfo

EPSS

Процентиль: 18%
0.00057
Низкий

7.5 High

CVSS3

Дефекты

CWE-200
NVD-CWE-noinfo