PT-2022-20523 · Discourse · Discourse-Chat

Zogstrip

·

Published

2022-06-21

·

Updated

2023-07-24

·

CVE-2022-31095

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions discourse-chat versions prior to 0.4
Description The issue affects the discourse-chat plugin for the Discourse application, allowing an attacker who knows the message ID for a channel they do not have access to, to view that message using the chat message lookup endpoint. This primarily affects direct message channels. There are no known workarounds for this issue.
Recommendations For versions prior to 0.4, update the plugin to a version 0.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the chat message lookup endpoint until the plugin can be updated.

Exploit

Fix

Missing Authorization

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2022-31095
GHSA-R979-JHP2-3F6H

Affected Products

Discourse-Chat