Source |
CVE Liste |
Identifiant |
8319456 |
Date de publication |
2023-03-17 15:15:12 (vue: 2023-03-17 17:07:13) |
Titre |
CVE-2023-23622 |
Texte |
Discourse is an open-source discussion platform. Prior to version 3.0.1 of the `stable` branch and version 3.1.0.beta2 of the `beta` and `tests-passed` branches, the count of topics displayed for a tag is a count of all regular topics regardless of whether the topic is in a read restricted category or not. As a result, any users can technically poll a sensitive tag to determine if a new topic is created in a category which the user does not have excess to. In version 3.0.1 of the `stable` branch and version 3.1.0.beta2 of the `beta` and `tests-passed` branches, the count of topics displayed for a tag defaults to only counting regular topics which are not in read restricted categories. Staff users will continue to see a count of all topics regardless of the topic's category read restrictions. |
Notes |
|
Envoyé |
Oui |
Condensat |
2023 23622 `beta` `stable` `tests all any are beta2 branch branches can categories category continue count counting created cve defaults determine discourse discussion displayed does excess have new not only open passed` platform poll prior read regardless regular restricted restrictions result see sensitive source staff tag technically topic topics user users version whether which will |
Tags |
|
Stories |
|
Move |
|