Discourse is an open source discussion platform. In versions prior to 2.7.7 there are two bugs which led to the post creator of a whisper post being revealed to non-staff users. 1: Staff users that creates a whisper post in a personal message is revealed to non-staff participants of the personal message even though the whisper post cannot be seen by them. 2: When a whisper post is before the last post in a post stream, deleting the last post will result in the creator of the whisper post to be revealed to non-staff users as the last poster of the topic.
We have discovered 396 live websites that are affected by CVE-2021-32788.
| Product | |
| Category | Message Boards |
| Vulnerable Domains | 396 live websites (8.57% of Discourse install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 19 versions ( 33% of all versions) |
| 257 websites | |
| 34 websites | |
| 12 websites | |
| 12 websites | |
| 10 websites | |
| 9 websites | |
| 6 websites | |
| 5 websites | |
| 3 websites |
| .com | 176 websites |
| .org | 57 websites |
| .net | 15 websites |
| .io | 14 websites |
| .co | 11 websites |
| .de | 8 websites |
| .com.br | 6 websites |
| .cn | 5 websites |
| .it | 4 websites |
| .ru | 4 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ******.********.com | **,*** | ||
| *********.***************.com | **,*** | ||
| *********.****.ly | ***,*** | ||
| *****.***********.com | ***,*** | ||
| *************.com | ***,*** | ||
| *****.com | ***,*** | ||
| *****.**********.org | ***,*** | ||
| ******.********.com | ***,*** | ||
| ***.******.com | ***,*** | ||
| *********.****************.com | ***,*** |
FAQ