Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2021-41082— Private message title and participating users leaked in discourse

Quick assessment

Affected
discourse discourse
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Discourse是一套开源的社区讨论平台。该平台包括社区、电子邮件和聊天室等功能。 Discourse 存在信息泄露漏洞,在受影响的版本中,任何包含群组的私人消息都将其标题和参与用户暴露给无权访问私人消息的用户。

CVSS 7.5 · High EPSS 1.79% · P77

Possible ATT&CK Techniques 1 AI

T1530 · Data from Cloud Storage
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2021-41082

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Private message title and participating users leaked in discourse
Source: CVE Program / CVE List V5
Vulnerability Description
Discourse is a platform for community discussion. In affected versions any private message that includes a group had its title and participating user exposed to users that do not have access to the private messages. However, access control for the private messages was not compromised as users were not able to view the posts in the leaked private message despite seeing it in their inbox. The problematic commit was reverted around 32 minutes after it was made. Users are encouraged to upgrade to the latest commit if they are running Discourse against the `tests-passed` branch.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
信息暴露
Source: CVE Program / CVE List V5
Vulnerability Title
Discourse 信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Discourse是一套开源的社区讨论平台。该平台包括社区、电子邮件和聊天室等功能。 Discourse 存在信息泄露漏洞,在受影响的版本中,任何包含群组的私人消息都将其标题和参与用户暴露给无权访问私人消息的用户。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
discourse discourse >= tests-passed = ddb4583, < tests-passed = 27bad28 -

II. Public POCs for CVE-2021-41082

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2021-41082

登录查看更多情报信息。

Patches & Fixes for CVE-2021-41082 (2)

Vendor Advisories for CVE-2021-41082 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2021-41082

No comments yet


Leave a comment