PT-2022-23155 · Discourse · Discourse

Highjomax

·

Published

2022-09-29

·

Updated

2024-03-06

·

CVE-2022-36068

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Discourse versions prior to 2.8.9 Discourse versions prior to 2.9.0.beta10
Description The issue allows a moderator to create new and edit existing themes using the API when they should not have this capability.
Recommendations For versions prior to 2.8.9, update to version 2.8.9 or later. For versions prior to 2.9.0.beta10, update to version 2.9.0.beta10 or later.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2022-36068
CVE-2022-36068
GHSA-6CRR-3662-263Q

Affected Products

Discourse