Improper access control in Discourse - CVE-2023-23622

 

Improper access control in Discourse - CVE-2023-23622

Published: March 17, 2023 / Updated: July 1, 2026


Vulnerability identifier: #VU136502
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-23622
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper access control in tag topic count handling when viewing tags. A remote attacker can poll a visible tag to determine whether new topics were created in read restricted categories to disclose sensitive information.

User interaction is required to view the tag information.


Affected software

Discourse

How to mitigate CVE-2023-23622

Install security update from vendor's website.

Discourse - addressed in versions 3.0.0, 3.1.0 beta1

External References

Related Security Bulletins