CVE-2022-39385
Users erroneously and transparently added to private messages in Discourse
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Discourse is the an open source discussion platform. In some rare cases users redeeming an invitation can be added as a participant to several private message topics that they should not be added to. They are not notified of this, it happens transparently in the background. This issue has been resolved in commit `a414520742` and will be included in future releases. Users are advised to upgrade. Users are also advised to set `SiteSetting.max_invites_per_day` to 0 until the patch is installed.
Discourse es una plataforma de discusión de código abierto. En algunos casos excepcionales, los usuarios que canjean una invitación pueden ser agregados como participantes a varios temas de mensajes privados a los que no se les debe agregar. No se les notifica esto, sucede de forma transparente en segundo plano. Este problema se resolvió en el commit "a414520742" y se incluirá en versiones futuras. Se recomienda a los usuarios que actualicen. También se recomienda a los usuarios que establezcan `SiteSetting.max_invites_per_day` en 0 hasta que se instale el parche.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-09-02 CVE Reserved
- 2022-11-14 CVE Published
- 2024-06-06 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- CWE-863: Incorrect Authorization
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://github.com/discourse/discourse/security/advisories/GHSA-gh5r-j595-qx48 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/discourse/discourse/commit/a414520742da8dc9dc976d4fb7b72dbd445813bb | 2022-11-17 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Discourse Search vendor "Discourse" | Discourse Search vendor "Discourse" for product "Discourse" | < 2.8.10 Search vendor "Discourse" for product "Discourse" and version " < 2.8.10" | - |
Affected
| ||||||
Discourse Search vendor "Discourse" | Discourse Search vendor "Discourse" for product "Discourse" | 2.9.0 Search vendor "Discourse" for product "Discourse" and version "2.9.0" | beta1 |
Affected
| ||||||
Discourse Search vendor "Discourse" | Discourse Search vendor "Discourse" for product "Discourse" | 2.9.0 Search vendor "Discourse" for product "Discourse" and version "2.9.0" | beta10 |
Affected
| ||||||
Discourse Search vendor "Discourse" | Discourse Search vendor "Discourse" for product "Discourse" | 2.9.0 Search vendor "Discourse" for product "Discourse" and version "2.9.0" | beta2 |
Affected
| ||||||
Discourse Search vendor "Discourse" | Discourse Search vendor "Discourse" for product "Discourse" | 2.9.0 Search vendor "Discourse" for product "Discourse" and version "2.9.0" | beta3 |
Affected
| ||||||
Discourse Search vendor "Discourse" | Discourse Search vendor "Discourse" for product "Discourse" | 2.9.0 Search vendor "Discourse" for product "Discourse" and version "2.9.0" | beta4 |
Affected
| ||||||
Discourse Search vendor "Discourse" | Discourse Search vendor "Discourse" for product "Discourse" | 2.9.0 Search vendor "Discourse" for product "Discourse" and version "2.9.0" | beta5 |
Affected
| ||||||
Discourse Search vendor "Discourse" | Discourse Search vendor "Discourse" for product "Discourse" | 2.9.0 Search vendor "Discourse" for product "Discourse" and version "2.9.0" | beta6 |
Affected
| ||||||
Discourse Search vendor "Discourse" | Discourse Search vendor "Discourse" for product "Discourse" | 2.9.0 Search vendor "Discourse" for product "Discourse" and version "2.9.0" | beta7 |
Affected
| ||||||
Discourse Search vendor "Discourse" | Discourse Search vendor "Discourse" for product "Discourse" | 2.9.0 Search vendor "Discourse" for product "Discourse" and version "2.9.0" | beta8 |
Affected
|