# 2.7.8：安全发布

**URL:** https://meta.discourse.org/t/2-7-8-security-release/202366
**Category:** Announcements
**Tags:** release-notes
**Created:** [2021年九月1日 17:21 UTC](https://meta.discourse.org/t/2-7-8-security-release/202366 "2021-09-01T17:21:21Z")
**Posts on this page:** 1
**Page:** 1

<div class="post-metadata">

### Author: ![jomaxro](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jomaxro/32/126216_2.png) [@jomaxro](https://meta.discourse.org/u/jomaxro)
#### Post date: [2021年九月1日 17:21 UTC](https://meta.discourse.org/t/2-7-8-security-release/202366/1 "2021-09-01T17:21:21Z")

</div>

## Discourse 2.7.8 稳定版发布

Discourse 强烈建议所有站点遵循 Discourse 的默认 tests-passed 分支。“stable”分支更侧重于_无变更_而非_无漏洞_——所有版本，包括 tests-passed 和 beta 版本，均已准备好投入生产使用。

### 变更内容

#### 安全：

- 清理 d-popover 属性（CVE-2021-37633）
- 当 EmailChangeRequest 被销毁时，销毁 EmailToken（CVE-2021-37693）
- 用户的主题阅读状态泄露给未授权客户端（CVE-2021-37703）
- 转义分类名称（CVE-2021-39161）
