CVE-2023-44391

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-44391
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-44391.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-44391
Aliases
Published
2023-10-16T21:22:24.719Z
Modified
2025-12-05T00:07:54.043020Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Prevent unauthorized access to summary details in Discourse
Details

Discourse is an open source platform for community discussion. User summaries are accessible for anonymous users even when hide_user_profiles_from_public is enabled. This problem has been patched in the 3.1.1 stable and 3.2.0.beta2 version of Discourse. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Database specific
{
    "cwe_ids": [
        "CWE-200"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/44xxx/CVE-2023-44391.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git /

Affected ranges