CVE-2023-45816

Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, there is an edge case where a bookmark reminder is sent and an unread notification is generated, but the underlying bookmarkable (e.g. post, topic, chat message) security has changed, making it so the user can no longer access the underlying resource. As of version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, bookmark reminders are now no longer sent if the user does not have access to the underlying bookmarkable, and also the unread bookmark notifications are always filtered by access. There are no known workarounds.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:discourse:discourse:*:*:*:*:stable:*:*:*
cpe:2.3:a:discourse:discourse:*:*:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:3.2.0:beta1:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:3.2.0:beta2:*:*:beta:*:*:*

History

16 Nov 2023, 19:38

Type Values Removed Values Added
References () https://github.com/discourse/discourse/security/advisories/GHSA-v9r6-92wp-f6cf - () https://github.com/discourse/discourse/security/advisories/GHSA-v9r6-92wp-f6cf - Vendor Advisory
References () https://github.com/discourse/discourse/commit/2c45b949ea0e9d6fa8e5af2dd07f6521ede08bf1 - () https://github.com/discourse/discourse/commit/2c45b949ea0e9d6fa8e5af2dd07f6521ede08bf1 - Patch
References () https://github.com/discourse/discourse/commit/3c5fb871c0f54af47679ae71ad449666b01d8216 - () https://github.com/discourse/discourse/commit/3c5fb871c0f54af47679ae71ad449666b01d8216 - Patch
CPE cpe:2.3:a:discourse:discourse:3.2.0:beta1:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:*:*:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:3.2.0:beta2:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:*:*:*:*:stable:*:*:*
First Time Discourse
Discourse discourse
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 3.3

10 Nov 2023, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-10 15:15

Updated : 2024-02-28 20:54


NVD link : CVE-2023-45816

Mitre link : CVE-2023-45816

CVE.ORG link : CVE-2023-45816


JSON object : View

Products Affected

discourse

  • discourse
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor