CVE-2023-43814

Source
https://cve.org/CVERecord?id=CVE-2023-43814
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-43814.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-43814
Aliases
Published
2023-10-16T21:09:16.620Z
Modified
2026-07-15T01:48:56.538981609Z
Severity
  • 3.7 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Exposure of poll options and votes to unauthorized users in Discourse
Details

Discourse is an open source platform for community discussion. Attackers with details specific to a poll in a topic can use the /polls/grouped_poll_results endpoint to view the content of options in the poll and the number of votes for groups of poll participants. This impacts private polls where the results were intended to only be viewable by authorized users. This issue is patched in the 3.1.1 stable and 3.2.0.beta2 versions of Discourse. There is no workaround for this issue apart from upgrading to the fixed version.

Database specific
{
    "cwe_ids": [
        "CWE-200",
        "CWE-284"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/43xxx/CVE-2023-43814.json"
}
References

Affected packages

Git / github.com/discourse/discourse

Affected ranges

Type
GIT
Repo
https://github.com/discourse/discourse
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "stable <= 3.1.1"
        },
        {
            "last_affected": "stable <= 3.1.1"
        },
        {
            "introduced": "beta <= 3.2.0.beta2"
        },
        {
            "last_affected": "beta <= 3.2.0.beta2"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

3.*
3.2.0-beta1
beta <= 3.*
beta <= 3.2.0.beta2
stable <= 3.*
stable <= 3.1.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-43814.json"