PT-2022-24824 · Discourse · Discourse

Jomaxro

·

Published

2022-09-29

·

Updated

2024-03-06

·

CVE-2022-39226

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Discourse versions prior to 2.8.9 Discourse versions prior to 2.9.0.beta10
Description A malicious actor can add large payloads of text into the Location and Website fields of a user profile, causing issues for other users when loading that profile.
Recommendations For versions prior to 2.8.9, update to version 2.8.9 or later on the stable branch. For versions prior to 2.9.0.beta10, update to version 2.9.0.beta10 or later on the beta and tests-passed branches.

Exploit

Fix

Allocation of Resources Without Limits

RCE

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2022-39226
CVE-2022-39226
GHSA-JW3Q-XG5G-QJRW

Affected Products

Discourse