CVE-2021-32788

Post creator of a whisper post can be revealed to non-staff users in Discourse

Discourse is an open source discussion platform. In versions prior to 2.7.7 there are two bugs which led to the post creator of a whisper post being revealed to non-staff users. 1: Staff users that creates a whisper post in a personal message is revealed to non-staff participants of the personal message even though the whisper post cannot be seen by them. 2: When a whisper post is before the last post in a post stream, deleting the last post will result in the creator of the whisper post to be revealed to non-staff users as the last poster of the topic.


We have discovered 396 live websites that are affected by CVE-2021-32788.

Run a Free Instant Scan




Affected Software

Product  Discourse
Category Message Boards
Vulnerable Domains396 live websites (8.57% of Discourse install base)
Vulnerable Versions
  • from 0 through 2.7.7
Vulnerable Versions Count19 versions ( 33% of all versions)


Common Weakness Enumeration

CWE-668 Exposure of Resource to Wrong Sphere



Details

  • Published - Jul 28, 2021
  • Updated - Aug 3, 2024

Website Distribution by Country

Number of websites using CVE-2021-32788
United States257 websites



Germany34 websites
China12 websites
Singapore12 websites
France10 websites
Brazil9 websites
GB6 websites
Russia5 websites
Canada3 websites

Website Distribution by TLD

Number of websites using CVE-2021-32788
.com176 websites
.org57 websites
.net15 websites
.io14 websites
.co11 websites
.de8 websites
.com.br6 websites
.cn5 websites
.it4 websites
.ru4 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2021-32788

Top websites that are affected by CVE-2021-32788. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.********.com United States**,***
*********.***************.com United States**,***
*********.****.ly United States***,***
*****.***********.com United States***,***
*************.com United States***,***
*****.com United States***,***
*****.**********.org Switzerland***,***
******.********.com United States***,***
***.******.com United States***,***
*********.****************.com United States***,***
See full domain list

FAQ

CVE-2021-32788 is Exposure of Resource to Wrong Sphere in Discourse
A total of 396 websites have been identified as vulnerable to CVE-2021-32788, based on global website indexing conducted by WebTechSurvey.
The Discourse is affected by the CVE-2021-32788 vulnerability.
Discourse versions up to 2.7.7 are vulnerable to CVE-2021-32788.
CVE-2021-32788 is resolved in version 2.7.7 of Discourse.