In version 2.9.0.beta14 of Discourse, an open-source discussion platform, maliciously embedded urls can leak an admin's digest of recent topics, possibly exposing private information. A patch is available for version 2.9.0.beta15. There are no known workarounds for this issue.
Score: 1.8
Priority: P4 - Informational (Low)
Score: 0.00032
Percentile:
0.0722
CVSS v3.1 Score: 5.5
Severity: MEDIUM