PT-2022-24923 · Discourse · Discourse Patreon Plugin+1

Jomaxro

·

Published

2022-10-26

·

Updated

2022-10-28

·

CVE-2022-39355

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Discourse Patreon plugin (affected versions not specified)
Description An improper authentication issue could be exploited to take control of a victim's forum account on sites with Patreon login enabled. This issue affects the synchronization between Discourse Groups and Patreon rewards. As a precautionary measure, Discourse accounts that have logged in with an unverified-email Patreon account will be logged out and asked to verify their email address on their next login.
Recommendations As a temporary workaround, consider disabling the Patreon integration and log out all users with associated Patreon accounts. Update the discourse-patreon plugin to a version that includes the patch commit number 846d012151514b35ce42a1636c7d70f6dcee879e.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-39355
GHSA-FVJ9-F67V-QPR4

Affected Products

Discourse
Discourse Patreon Plugin