CVE-2022-46168
- EPSS 0.26%
- Veröffentlicht 05.01.2023 18:15:08
- Zuletzt bearbeitet 21.11.2024 07:30:14
Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 2.9.0.beta15 on the `beta` and `tests-passed` branches, recipients of a group SMTP email could see the email addresses of all other users in...
CVE-2022-46159
- EPSS 0.36%
- Veröffentlicht 02.12.2022 15:15:10
- Zuletzt bearbeitet 21.11.2024 07:30:13
Discourse is an open-source discussion platform. In version 2.8.13 and prior on the `stable` branch and version 2.9.0.beta14 and prior on the `beta` and `tests-passed` branches, any authenticated user can create an unlisted topic. These topics, which...
CVE-2022-46150
- EPSS 0.25%
- Veröffentlicht 29.11.2022 18:15:10
- Zuletzt bearbeitet 21.11.2024 07:30:12
Discourse is an open-source discussion platform. Prior to version 2.8.13 of the `stable` branch and version 2.9.0.beta14 of the `beta` and `tests-passed` branches, unauthorized users may learn of the existence of hidden tags and that they have been a...
CVE-2022-46148
- EPSS 0.4%
- Veröffentlicht 29.11.2022 17:15:11
- Zuletzt bearbeitet 21.11.2024 07:30:12
Discourse is an open-source messaging platform. In versions 2.8.10 and prior on the `stable` branch and versions 2.9.0.beta11 and prior on the `beta` and `tests-passed` branches, users composing malicious messages and navigating to drafts page could ...
CVE-2022-41921
- EPSS 0.3%
- Veröffentlicht 28.11.2022 15:15:10
- Zuletzt bearbeitet 21.11.2024 07:24:04
Discourse is an open-source discussion platform. Prior to version 2.9.0.beta13, users can post chat messages of an unlimited length, which can cause a denial of service for other users when posting huge amounts of text. Users should upgrade to versio...
CVE-2022-41944
- EPSS 0.19%
- Veröffentlicht 28.11.2022 15:15:10
- Zuletzt bearbeitet 21.11.2024 07:24:07
Discourse is an open-source discussion platform. In stable versions prior to 2.8.12 and beta or tests-passed versions prior to 2.9.0.beta.13, under certain conditions, a user can see notifications for topics they no longer have access to. If there is...
CVE-2022-39385
- EPSS 0.24%
- Veröffentlicht 14.11.2022 21:15:15
- Zuletzt bearbeitet 21.11.2024 07:18:11
Discourse is the an open source discussion platform. In some rare cases users redeeming an invitation can be added as a participant to several private message topics that they should not be added to. They are not notified of this, it happens transpar...
CVE-2022-39241
- EPSS 0.29%
- Veröffentlicht 02.11.2022 17:15:17
- Zuletzt bearbeitet 21.11.2024 07:17:51
Discourse is a platform for community discussion. A malicious admin could use this vulnerability to perform port enumeration on the local host or other hosts on the internal network, as well as against hosts on the Internet. Latest `stable`, `beta`, ...
CVE-2022-39356
- EPSS 0.31%
- Veröffentlicht 02.11.2022 17:15:17
- Zuletzt bearbeitet 21.11.2024 07:18:06
Discourse is a platform for community discussion. Users who receive an invitation link that is not scoped to a single email address can enter any non-admin user's email and gain access to their account when accepting the invitation. All users should ...
CVE-2022-39378
- EPSS 0.27%
- Veröffentlicht 02.11.2022 17:15:17
- Zuletzt bearbeitet 21.11.2024 07:18:10
Discourse is a platform for community discussion. Under certain conditions, a user badge may have been awarded based on a user's activity in a topic with restricted access. Before this vulnerability was disclosed, the topic title of the topic associa...