# 2.7.13: Security Release

**URL:** https://meta.discourse.org/t/2-7-13-security-release/214753
**Category:** Announcements
**Tags:** release-notes
**Created:** [January 13, 2022, 3:24pm UTC](https://meta.discourse.org/t/2-7-13-security-release/214753 "2022-01-13T15:24:14Z")
**Posts on this page:** 1
**Page:** 1

<div class="post-metadata">

### Author: ![jomaxro](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jomaxro/32/126216_2.png) [@jomaxro](https://meta.discourse.org/u/jomaxro)
#### Post date: [January 13, 2022, 3:24pm UTC](https://meta.discourse.org/t/2-7-13-security-release/214753/1 "2022-01-13T15:24:14Z")

</div>

## Discourse 2.7.13 Stable Release

Discourse strongly recommends that all sites follow the default tests-passed branch of Discourse. The “stable” branch is more focused on _lack of change_ than _lack of bugs_ - all releases, including those on tests-passed and beta are production ready.

### Changes

#### Security:

- Do not sign in unapproved users (CVE-2022-21684)
- Advanced group search did not respect visibility of groups. (CVE-2022-21677)
- Hide user’s bio if profile is restricted (CVE-2022-21678)
- Only show user suggestions with regular post (CVE-2022-21642)
