CVE-2023-22453
Description
Discourse is an option source discussion platform. Prior to version 2.8.14 on the stable
branch and version 3.0.0.beta16 on the beta
and tests-passed
branches, the number of times a user posted in an arbitrary topic is exposed to unauthorized users through the /u/username.json
endpoint. The issue is patched in version 2.8.14 and 3.0.0.beta16. There is no known workaround.
- CVSS Version 3.1
nvd
CVE ID: CVE-2023-22453
Base Score: 5.3
Base Severity: MEDIUM
Vector String:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Impact Score: 1.4
Exploitability Score: 3.9
github
CVE ID: CVE-2023-22453
Base Score: 5.3
Base Severity: MEDIUM
Vector String:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Impact Score: 1.4
Exploitability Score: 3.9