CVE-2023-23624
Last modified
CVE-2023-23624 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and version 3.1.0.beta2 on the `beta` and `tests-passed` branches, someone can use the `exclude_tag param` to filter out topics and deduce which ones were using a specific hidden tag. EPSS estimates a 0.59% chance of exploitation in the next 30 days.
Description
Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and version 3.1.0.beta2 on the `beta` and `tests-passed` branches, someone can use the `exclude_tag param` to filter out topics and deduce which ones were using a specific hidden tag. This affects any Discourse site using hidden tags in public categories. This issue is patched in version 3.0.1 on the `stable` branch and version 3.1.0.beta2 on the `beta` and `tests-passed` branches. As a workaround, secure any categories that are using hidden tags, change any existing hidden tags to not include private data, or remove any hidden tags currently in use.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Discourse | Discourse | < 3.0.1 | — |
| Discourse | Discourse | 1.1.0 | Beta1 |
| Discourse | Discourse | 1.2.0 | Beta1 |
| Discourse | Discourse | 1.3.0 | Beta1 |
| Discourse | Discourse | 1.4.0 | Beta1 |
| Discourse | Discourse | 1.5.0 | Beta1 |
| Discourse | Discourse | 1.6.0 | Beta1 |
| Discourse | Discourse | 1.7.0 | Beta1 |
| Discourse | Discourse | 1.8.0 | Beta1 |
| Discourse | Discourse | 1.9.0 | Beta1 |
| Discourse | Discourse | 2.0.0 | Beta1 |
| Discourse | Discourse | 2.1.0 | Beta1 |
| Discourse | Discourse | 2.2.0 | Beta1 |
| Discourse | Discourse | 2.3.0 | Beta1 |
| Discourse | Discourse | 2.4.0 | Beta1 |
| Discourse | Discourse | 2.5.0 | Beta1 |
| Discourse | Discourse | 2.6.0 | Beta1 |
| Discourse | Discourse | 2.7.0 | Beta1 |
| Discourse | Discourse | 2.8.0 | Beta1 |
| Discourse | Discourse | 2.9.0 | Beta1 |
| Discourse | Discourse | 3.0.0 | Beta15 |
| Discourse | Discourse | 3.1.0 | Beta1 |
References
- https://github.com/discourse/discourse/pull/20006Issue Tracking, Patch
- https://github.com/discourse/discourse/security/advisories/GHSA-qgj5-g5vf-fm7qThird Party Advisory
- https://github.com/discourse/discourse/pull/20006Issue Tracking, Patch
- https://github.com/discourse/discourse/security/advisories/GHSA-qgj5-g5vf-fm7qThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-23624?
How severe is CVE-2023-23624?
How do I fix CVE-2023-23624?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-23619Modelina is a library for generating data models based on in…8.8
- CVE-2023-2362The Float menu WordPress plugin before 5.0.2, Bubble Menu Wo…6.1
- CVE-2023-23620Discourse is an open-source discussion platform. Prior to ve…5.3
- CVE-2023-23621Discourse is an open-source discussion platform. Prior to ve…7.5
- CVE-2023-23622Discourse is an open-source discussion platform. Prior to ve…4.3
- CVE-2023-23623Electron is a framework which lets you write cross-platform …9.8
- CVE-2023-23625go-unixfs is an implementation of a unix-like filesystem on …7.5
- CVE-2023-23626go-bitfield is a simple bitfield package for the go language…7.5
- CVE-2023-23627Sanitize is an allowlist-based HTML and CSS sanitizer. Versi…6.1
- CVE-2023-23628Metabase is an open source data analytics platform. Affected…4.1
- CVE-2023-23629Metabase is an open source data analytics platform. Affected…6.3
- CVE-2023-2363A vulnerability, which was classified as critical, has been …9.8
Are you affected by CVE-2023-23624?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
