# 2.8.10: Security Release

**URL:** https://meta.discourse.org/t/2-8-10-security-release/243761
**Category:** Announcements
**Tags:** release-notes
**Created:** [November 1, 2022, 5:34pm UTC](https://meta.discourse.org/t/2-8-10-security-release/243761 "2022-11-01T17:34:32Z")
**Posts on this page:** 1
**Page:** 1

<div class="post-metadata">

### Author: ![jomaxro](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jomaxro/32/126216_2.png) [@jomaxro](https://meta.discourse.org/u/jomaxro)
#### Post date: [November 1, 2022, 5:34pm UTC](https://meta.discourse.org/t/2-8-10-security-release/243761/1 "2022-11-01T17:34:32Z")

</div>

## Discourse 2.8.10 Stable Release

Discourse strongly recommends that all sites follow the default tests-passed branch of Discourse. The “stable” branch is more focused on _lack of change_ than _lack of bugs_ - all releases, including those on tests-passed and beta are production ready.

### Changes

#### Security:

- Restrict display of topic titles associated with user badges [CVE-2022-39378](https://github.com/discourse/discourse/security/advisories/GHSA-2gvq-27h6-4h5f)
- Expand and improve SSRF Protections [CVE-2022-39241](https://github.com/discourse/discourse/security/advisories/GHSA-rcc5-28r3-23rr)
- Fix invite link email validation [CVE-2022-39356](https://github.com/discourse/discourse/security/advisories/GHSA-x8w7-rwmr-w278)

##### Plugin Security Updates

Multiple plugins have also received security fixes. Be sure to update plugins in addition to Discourse.

- Patreon: [Critical security fix for the discourse-patreon plugin](https://meta.discourse.org/t/critical-security-fix-for-the-discourse-patreon-plugin/242999)
- Chat: Channel name and description susceptible to XSS [CVE-2022-39279](https://github.com/discourse/discourse-chat/security/advisories/GHSA-qp62-8m3c-9jgj)
- Chat Integration: Insufficient Server Side Request Forgery protections [CVE-2022-39241](https://github.com/discourse/discourse-chat-integration/security/advisories/GHSA-xmc4-3rxg-q8jx)
- OAuth2 Basic: Insufficient Server Side Request Forgery protections [CVE-2022-39241](https://github.com/discourse/discourse-oauth2-basic/security/advisories/GHSA-qj5f-8cm8-rhf8)
- OpenID Connect: Insufficient Server Side Request Forgery protections [CVE-2022-39241](https://github.com/discourse/discourse-openid-connect/security/advisories/GHSA-xp93-7vr3-72c5)
