PT-2022-24944 · Discourse · Discourse

Highjomaxro

·

Published

2022-11-14

·

Updated

2024-03-06

·

CVE-2022-39385

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Discourse (affected versions not specified)
Description The issue affects the Discourse open source discussion platform, where in rare cases, users redeeming an invitation can be added as a participant to several private message topics they should not have access to, without being notified. This happens transparently in the background.
Recommendations To resolve the issue, users are advised to upgrade to a future release that includes the fix. As a temporary workaround, consider setting SiteSetting.max invites per day to 0 until the patch is installed.

Exploit

Fix

Incorrect Authorization

Information Disclosure

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2022-39385
CVE-2022-39385
GHSA-GH5R-J595-QX48

Affected Products

Discourse