PT-2022-27764 · Discourse · Discourse

1Twodrei

·

Published

2022-11-29

·

Updated

2024-03-06

·

CVE-2022-46148

CVSS v3.1

7.1

High

VectorAV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Discourse versions 2.8.10 and prior Discourse versions 2.9.0.beta11 and prior
Description Discourse is an open-source messaging platform. Users composing malicious messages and navigating to the drafts page could self-XSS. This issue can lead to a full XSS on sites which have modified or disabled Discourse’s default Content Security Policy.
Recommendations For versions 2.8.10 and prior, update to the latest stable version of Discourse. For versions 2.9.0.beta11 and prior, update to the latest beta or tests-passed version of Discourse. As a temporary workaround, consider restricting access to the drafts page until a patch is available. Avoid using modified or disabled Content Security Policy configurations to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2022-46148
CVE-2022-46148
GHSA-C5H6-6GG5-84FH

Affected Products

Discourse