8.8

CVE-2022-21684

User can bypass approval when invited to Discourse

Discourse is an open source discussion platform. Versions prior to 2.7.13 in `stable`, 2.8.0.beta11 in `beta`, and 2.8.0.beta11 in `tests-passed` allow some users to log in to a community before they should be able to do so. A user invited via email to a forum with `must_approve_users` enabled is going to be automatically logged in, bypassing the check that does not allow unapproved users to sign in. They will be able to do everything an approved user can do. If they logout, they cannot log back in. This issue is patched in the `stable` version 2.7.13, `beta` version 2.8.0.beta11, and `tests-passed` version 2.8.0.beta11. One may disable invites as a workaround. Administrators can increase `min_trust_level_to_allow_invite` to reduce the attack surface to more trusted users.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Discourse ≫ Discourse Version < 2.7.13
Discourse ≫ Discourse Version 2.8.0 Update beta1
Discourse ≫ Discourse Version 2.8.0 Update beta10
Discourse ≫ Discourse Version 2.8.0 Update beta2
Discourse ≫ Discourse Version 2.8.0 Update beta3
Discourse ≫ Discourse Version 2.8.0 Update beta4
Discourse ≫ Discourse Version 2.8.0 Update beta5
Discourse ≫ Discourse Version 2.8.0 Update beta6
Discourse ≫ Discourse Version 2.8.0 Update beta7
Discourse ≫ Discourse Version 2.8.0 Update beta8
Discourse ≫ Discourse Version 2.8.0 Update beta9
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.83% 0.538
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 6 6.8 6.4
AV:N/AC:M/Au:S/C:P/I:P/A:P
security-advisories@github.com 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

https://github.com/discourse/discourse/commit/584c6a2e8bc705072b09a9c4b55126d6f8ed4ad2
Patch
Third Party Advisory
https://github.com/discourse/discourse/security/advisories/GHSA-p63q-jp48-h8xh
Patch
Third Party Advisory
https://meta.discourse.org/t/invite-redemption-allowed-user-to-access-forum-before-approval/214328
Patch
Vendor Advisory
Issue Tracking