5.5

CVE-2022-23546

Discourse vulnerable to private topic leak via email#send_digest

In version 2.9.0.beta14 of Discourse, an open-source discussion platform, maliciously embedded urls can leak an admin's digest of recent topics, possibly exposing private information. A patch is available for version 2.9.0.beta15. There are no known workarounds for this issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Discourse ≫ Discourse Version < 2.9.0
Discourse ≫ Discourse Version 2.9.0 Update beta1
Discourse ≫ Discourse Version 2.9.0 Update beta10
Discourse ≫ Discourse Version 2.9.0 Update beta11
Discourse ≫ Discourse Version 2.9.0 Update beta12
Discourse ≫ Discourse Version 2.9.0 Update beta13
Discourse ≫ Discourse Version 2.9.0 Update beta14
Discourse ≫ Discourse Version 2.9.0 Update beta2
Discourse ≫ Discourse Version 2.9.0 Update beta3
Discourse ≫ Discourse Version 2.9.0 Update beta4
Discourse ≫ Discourse Version 2.9.0 Update beta5
Discourse ≫ Discourse Version 2.9.0 Update beta6
Discourse ≫ Discourse Version 2.9.0 Update beta7
Discourse ≫ Discourse Version 2.9.0 Update beta8
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.28% 0.195
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
security-advisories@github.com 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

https://github.com/discourse/discourse/commit/cf862e736565c6fa905c12b5dbe63d0bd056efb8
Patch
Third Party Advisory
https://github.com/discourse/discourse/security/advisories/GHSA-q9jp-xv4g-328f
Third Party Advisory