41821
(41821)
June 29, 2022, 11:58pm
1
hello,
We’ve received an alert from this CVE that an instance of discourse is vulnerable to https://www.cve.org/CVERecord?id=CVE-2022-31096
It is said that the fix is in 2.9.0.beta6 but I’m unable to find and upgrade to that version. Is anyone else having this problem?
Benjamin_D
(Benjamin Decotte)
June 30, 2022, 5:11am
3
pfaffman
(Jay Pfaffman)
June 30, 2022, 11:02am
8
You can upgrade now and that commit will be applied. It’s not a critical security issue, so they didn’t bump the version to push it out.
Osama
July 4, 2022, 8:49am
9
We do a beta bump for a high severity CVE shortly after the fix is released, but we missed to do that for the last CVE (CVE-2022-31096). We released 2.9.0.beta6 last week (Thursday) so this should be resolved now.
New features in 2.9.0.beta6
Whispers now support groups
Whispers are a great way for staff to communicate within a topic, without their post becoming public. Staff might share their thoughts on how to reply to a post, or discuss with each other whether to close a topic.
Historically, whispers were a staff-only features. Users needed to be admins or moderators to see (and post) whispers. Now, using the whispers allowed groups site setting, additional groups can be granted permission to whisper.
…