Discourse is an open source platform for community discussion. Moderators can see the Screened emails list in the admin dashboard, and through that can learn the email of a user. This problem is patched in the latest version of Discourse. Users unable to upgrade should remove moderator role from untrusted users.
History

Thu, 19 Dec 2024 19:30:00 +0000

Type Values Removed Values Added
Description Discourse is an open source platform for community discussion. Moderators can see the Screened emails list in the admin dashboard, and through that can learn the email of a user. This problem is patched in the latest version of Discourse. Users unable to upgrade should remove moderator role from untrusted users.
Title Moderators can view Screened emails even when the “moderators view emails” option is disabled in Discourse
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 2.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-12-19T19:13:51.333Z

Updated: 2024-12-20T20:01:32.479Z

Reserved: 2024-11-14T15:05:46.767Z

Link: CVE-2024-52589

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2024-12-19T20:15:07.337

Modified: 2024-12-19T20:15:07.337

Link: CVE-2024-52589

cve-icon Redhat

No data.