CVE-2022-31095
Exposure of Sensitive Information in discourse-chat
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
discourse-chat is a chat plugin for the Discourse application. Versions prior to 0.4 are vulnerable to an exposure of sensitive information, where an attacker who knows the message ID for a channel they do not have access to can view that message using the chat message lookup endpoint, primarily affecting direct message channels. There are no known workarounds for this issue, and users are advised to update the plugin.
discourse-chat es un plugin de chat para la aplicación Discourse. Las versiones anteriores a 0.4 son vulnerables a una exposición de información confidencial, en la que un atacante que conoce el ID del mensaje de un canal al que no presenta acceso puede visualizar ese mensaje usando el endpoint de búsqueda de mensajes de chat, lo que afecta principalmente a los canales de mensajes directos. No se presentan mitigaciones conocidas para este problema, y es aconsejado a usuarios actualizar el plugin
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-05-18 CVE Reserved
- 2022-06-21 CVE Published
- 2024-01-12 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- CWE-862: Missing Authorization
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://github.com/discourse/discourse-chat/security/advisories/GHSA-r979-jhp2-3f6h | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Discourse Search vendor "Discourse" | Discourse-chat Search vendor "Discourse" for product "Discourse-chat" | < 0.4 Search vendor "Discourse" for product "Discourse-chat" and version " < 0.4" | discourse |
Affected
|