# Discourse-patreon vulnerability?

**URL:** https://meta.discourse.org/t/discourse-patreon-vulnerability/243030
**Category:** Community Building
**Created:** [October 27, 2022, 12:37am UTC](https://meta.discourse.org/t/discourse-patreon-vulnerability/243030 "2022-10-27T00:37:49Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![Brian4](https://avatars.discourse-cdn.com/v4/letter/b/ea5d25/32.png) [@Brian4](https://meta.discourse.org/u/Brian4)
#### Post date: [October 27, 2022, 12:37am UTC](https://meta.discourse.org/t/discourse-patreon-vulnerability/243030/1 "2022-10-27T00:37:49Z")

</div>

Joplin just posted that they had a vulnerability and user list was leaked.

Is there any more information about what happened?

> **[Our Discourse forum database was breached](https://discourse.joplinapp.org/t/our-discourse-forum-database-was-breached/27969)**
>
> Unfortunately we have to announce that our Discourse forum was breached on 25/10/2022. A group of hackers exploited a zero-day vulnerability in Discourse and got elevated access, which they then used to steal the user database. The stolen data...

---

<div class="post-metadata">

### Author: ![supermathie](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/supermathie/32/507518_2.png) [@supermathie](https://meta.discourse.org/u/supermathie)
#### Post date: [October 27, 2022, 12:46am UTC](https://meta.discourse.org/t/discourse-patreon-vulnerability/243030/2 "2022-10-27T00:46:48Z")

</div>

Our security advisory for this is here:

> **[Improper validation of email during Patreon authentication](https://github.com/discourse/discourse-patreon/security/advisories/GHSA-fvj9-f67v-qpr4)**
>
> \### Impact
> On sites with Patreon login enabled, this vulnerability could be used to take control of a victim's forum account. 
> 
> \### Patches
> This vulnerability is patched in the latest version o...

---

<div class="post-metadata">

### Author: ![Brian4](https://avatars.discourse-cdn.com/v4/letter/b/ea5d25/32.png) [@Brian4](https://meta.discourse.org/u/Brian4)
#### Post date: [October 27, 2022, 1:00am UTC](https://meta.discourse.org/t/discourse-patreon-vulnerability/243030/3 "2022-10-27T01:00:43Z")

</div>

Thank you I looked quite a bit but couldn’t find anything

---

<div class="post-metadata">

### Author: ![Brian4](https://avatars.discourse-cdn.com/v4/letter/b/ea5d25/32.png) [@Brian4](https://meta.discourse.org/u/Brian4)
#### Post date: [October 27, 2022, 1:07am UTC](https://meta.discourse.org/t/discourse-patreon-vulnerability/243030/4 "2022-10-27T01:07:18Z")

</div>

I looked at the discourse GitHub but didn’t occur to me to check the plugin pages. Is there a best way to look for vulnerability across the board (discourse+plugins)? Whether an RSS feed or status page or?
