PT-2022-24828 · Discourse · Discourse
Lowjomaxro
·
Published
2022-09-29
·
Updated
2024-03-06
·
CVE-2022-39232
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Discourse versions 2.9.0.beta5 through 2.9.0.beta9
Description
The issue arises when an incomplete quote generates a JavaScript error, potentially crashing the current page in the browser. This occurs in certain cases and is related to how the platform handles quotes. The problem is resolved in version 2.9.0.beta10, which includes a fix and additional tests to prevent incomplete quotes from causing issues.
Recommendations
For versions 2.9.0.beta5 through 2.9.0.beta9, update to version 2.9.0.beta10 to resolve the issue.
As a temporary workaround for affected versions, the quote can be fixed via the rails console.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Discourse