关键漏洞信息 漏洞标题 Users are able to see their own whispers even after being removed from a group that has been configured to see whispers 严重性 等级: Moderate CVSS v4 base metrics: 6.3 / 10 影响版本 受影响版本: - stable = 3.4.6 - tests-passed >= 3.5.0.beta8-dev 描述与影响 The visibility of posts typed whisper is controlled via the whispers_allowed_groups site setting. Only users that belong to groups specified in the site setting are allowed to view posts typed whisper. However, it has been discovered that users can continue to see their own whispers even after losing visibility of posts typed whisper. 修复措施 This issue is patched in the latest stable, beta and tests-passed versions of Discourse. 绕过方法 None. 参考资料 None. CVE ID CVE-2025-49845 弱点 No CWEs