CVE-2022-24850
Category group permissions leaked in Discourse
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Discourse is an open source platform for community discussion. A category's group permissions settings can be viewed by anyone that has access to the category. As a result, a normal user is able to see whether a group has read/write permissions in the category even though the information should only be available to the users that can manage a category. This issue is patched in the latest stable, beta and tests-passed versions of Discourse. There are no workarounds for this problem.
Discourse es una plataforma de código abierto para el debate comunitario. La configuración de los permisos de grupo de una categoría puede ser visualizada por cualquiera que tenga acceso a la categoría. Como resultado, un usuario normal es capaz de visualizar si un grupo presenta permisos de lectura/escritura en la categoría aunque la información sólo debería estar disponible para usuarios que pueden administrar una categoría. Este problema está parcheado en las últimas versiones estables, beta y de prueba de Discourse. No se presentan medidas de mitigación para este problema
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-02-10 CVE Reserved
- 2022-04-14 CVE Published
- 2023-11-05 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://github.com/discourse/discourse/security/advisories/GHSA-34xr-ff4w-mcpf | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Discourse Search vendor "Discourse" | Discourse Search vendor "Discourse" for product "Discourse" | < 2.8.2 Search vendor "Discourse" for product "Discourse" and version " < 2.8.2" | - |
Affected
| ||||||
Discourse Search vendor "Discourse" | Discourse Search vendor "Discourse" for product "Discourse" | 2.9.0 Search vendor "Discourse" for product "Discourse" and version "2.9.0" | beta1 |
Affected
| ||||||
Discourse Search vendor "Discourse" | Discourse Search vendor "Discourse" for product "Discourse" | 2.9.0 Search vendor "Discourse" for product "Discourse" and version "2.9.0" | beta2 |
Affected
| ||||||
Discourse Search vendor "Discourse" | Discourse Search vendor "Discourse" for product "Discourse" | 2.9.0 Search vendor "Discourse" for product "Discourse" and version "2.9.0" | beta3 |
Affected
|