PT-2022-24944 · Discourse · Discourse
Highjomaxro
·
Published
2022-11-14
·
Updated
2024-03-06
·
CVE-2022-39385
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Discourse (affected versions not specified)
Description
The issue affects the Discourse open source discussion platform, where in rare cases, users redeeming an invitation can be added as a participant to several private message topics they should not have access to, without being notified. This happens transparently in the background.
Recommendations
To resolve the issue, users are advised to upgrade to a future release that includes the fix.
As a temporary workaround, consider setting
SiteSetting.max invites per day to 0 until the patch is installed.Exploit
Fix
Incorrect Authorization
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Discourse