Discourse 2.8.10 Stable Release
Discourse strongly recommends that all sites follow the default tests-passed branch of Discourse. The “stable” branch is more focused on lack of change than lack of bugs - all releases, including those on tests-passed and beta are production ready.
Changes
Security:
- Restrict display of topic titles associated with user badges CVE-2022-39378
- Expand and improve SSRF Protections CVE-2022-39241
- Fix invite link email validation CVE-2022-39356
Plugin Security Updates
Multiple plugins have also received security fixes. Be sure to update plugins in addition to Discourse.
- Patreon: Critical security fix for the discourse-patreon plugin
- Chat: Channel name and description susceptible to XSS CVE-2022-39279
- Chat Integration: Insufficient Server Side Request Forgery protections CVE-2022-39241
- OAuth2 Basic: Insufficient Server Side Request Forgery protections CVE-2022-39241
- OpenID Connect: Insufficient Server Side Request Forgery protections CVE-2022-39241