Discourse is an open-source discussion platform. Prior to version 2.8.4 in the stable branch and version 2.9.0.beta5 in the beta and tests-passed branches, banner topic data is exposed on login-required sites. This issue is patched in version 2.8.4 in the stable branch and version 2.9.0.beta5 in the beta and tests-passed branches of Discourse. As a workaround, one may disable banners.
{
"cwe_ids": [
"CWE-200"
]
}{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "stable < 2.8.4"
}
]
}