8.8

CVE-2022-39356

Discourse user account takeover via email and invite link

Discourse is a platform for community discussion. Users who receive an invitation link that is not scoped to a single email address can enter any non-admin user's email and gain access to their account when accepting the invitation. All users should upgrade to the latest version. A workaround is temporarily disabling invitations with `SiteSetting.max_invites_per_day = 0` or scope them to individual email addresses.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Discourse ≫ Discourse Version < 2.8.10
Discourse ≫ Discourse Version 2.9.0 Update beta1
Discourse ≫ Discourse Version 2.9.0 Update beta10
Discourse ≫ Discourse Version 2.9.0 Update beta2
Discourse ≫ Discourse Version 2.9.0 Update beta3
Discourse ≫ Discourse Version 2.9.0 Update beta4
Discourse ≫ Discourse Version 2.9.0 Update beta5
Discourse ≫ Discourse Version 2.9.0 Update beta6
Discourse ≫ Discourse Version 2.9.0 Update beta7
Discourse ≫ Discourse Version 2.9.0 Update beta8
Discourse ≫ Discourse Version 2.9.0 Update beta9
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.58% 0.449
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
security-advisories@github.com 8.9 2.3 6
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L
CWE-285 Improper Authorization

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

https://github.com/discourse/discourse/pull/18817
Patch
Third Party Advisory
https://github.com/discourse/discourse/security/advisories/GHSA-x8w7-rwmr-w278
Third Party Advisory