漏洞标题
未阅读的书签提醒通知,用户无法访问时可见
漏洞描述信息
未读书签提醒通知,用户无法访问,可以查看
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
漏洞类别
将资源暴露给错误范围
漏洞标题
Unread bookmark reminder notifications that the user cannot access can be seen
漏洞描述信息
Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, there is an edge case where a bookmark reminder is sent and an unread notification is generated, but the underlying bookmarkable (e.g. post, topic, chat message) security has changed, making it so the user can no longer access the underlying resource. As of version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, bookmark reminders are now no longer sent if the user does not have access to the underlying bookmarkable, and also the unread bookmark notifications are always filtered by access. There are no known workarounds.
CVSS信息
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
漏洞类别
信息暴露
漏洞标题
Discourse 安全漏洞
漏洞描述信息
Discourse是一套开源的社区讨论平台。该平台包括社区、电子邮件和聊天室等功能。 Discourse 3.1.3 版本之前存在安全漏洞,该漏洞源于有一种特殊情况,可以使用户无法再访问底层资源。
CVSS信息
N/A
漏洞类别
其他