PT-2022-16940 · Discourse · Discourse Assign

Pmusaraj

·

Published

2022-04-26

·

Updated

2022-05-06

·

CVE-2022-24866

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Discourse Assign versions prior to 1.0.1
Description The UserBookmarkSerializer in Discourse Assign serialized the whole User / Group object, which leaked some private information. This data was only accessible to people who could view assignment info, limited to staff by default, but for sites with assign features enabled publicly, the data was accessible to more people than just staff.
Recommendations For versions prior to 1.0.1, update to version 1.0.1 to resolve the issue. As a temporary workaround, consider restricting access to assignment info to minimize the risk of exploitation.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-24866
GHSA-9XHF-WVJX-F5W9

Affected Products

Discourse Assign