CVE-2022-39232
- EPSS 0.57%
- Veröffentlicht 29.09.2022 21:15:11
- Zuletzt bearbeitet 21.11.2024 07:17:50
Discourse is an open source discussion platform. Starting with version 2.9.0.beta5 and prior to version 2.9.0.beta10, an incomplete quote can generate a JavaScript error which will crash the current page in the browser in some cases. Version 2.9.0.be...
CVE-2022-36068
- EPSS 0.34%
- Veröffentlicht 29.09.2022 20:15:13
- Zuletzt bearbeitet 21.11.2024 07:12:18
Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.beta10 on the `beta` and `tests-passed` branches, a moderator can create new and edit existing themes by using the API when they sho...
CVE-2022-39226
- EPSS 0.5%
- Veröffentlicht 29.09.2022 20:15:13
- Zuletzt bearbeitet 21.11.2024 07:17:49
Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.beta10 on the `beta` and `tests-passed` branches, a malicious actor can add large payloads of text into the Location and Website fie...
CVE-2022-36066
- EPSS 3.57%
- Veröffentlicht 29.09.2022 20:15:09
- Zuletzt bearbeitet 21.11.2024 07:12:18
Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.beta10 on the `beta` and `tests-passed` branches, admins can upload a maliciously crafted Zip or Gzip Tar archive to write files at ...
CVE-2022-37458
- EPSS 0.65%
- Veröffentlicht 02.09.2022 12:15:11
- Zuletzt bearbeitet 21.11.2024 07:15:01
Discourse through 2.8.7 allows admins to send invitations to arbitrary email addresses at an unlimited rate.
CVE-2022-31182
- EPSS 0.38%
- Veröffentlicht 01.08.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 07:04:04
Discourse is the an open source discussion platform. In affected versions a maliciously crafted request for static assets could cause error responses to be cached by Discourse's default NGINX proxy configuration. A corrected NGINX configuration is in...
CVE-2022-31184
- EPSS 0.35%
- Veröffentlicht 01.08.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 07:04:04
Discourse is the an open source discussion platform. In affected versions an email activation route can be abused to send mass spam emails. A fix has been included in the latest stable, beta and tests-passed versions of Discourse which rate limits em...
CVE-2022-31096
- EPSS 0.27%
- Veröffentlicht 27.06.2022 22:15:09
- Zuletzt bearbeitet 21.11.2024 07:03:53
Discourse is an open source discussion platform. Under certain conditions, a logged in user can redeem an invite with an email that either doesn't match the invite's email or does not adhere to the email domain restriction of an invite link. The impa...
CVE-2022-31060
- EPSS 0.37%
- Veröffentlicht 14.06.2022 21:15:16
- Zuletzt bearbeitet 21.11.2024 07:03:48
Discourse is an open-source discussion platform. Prior to version 2.8.4 in the `stable` branch and version `2.9.0.beta5` in the `beta` and `tests-passed` branches, banner topic data is exposed on login-required sites. This issue is patched in version...
CVE-2022-31025
- EPSS 0.26%
- Veröffentlicht 07.06.2022 15:15:09
- Zuletzt bearbeitet 21.11.2024 07:03:44
Discourse is an open source platform for community discussion. Prior to version 2.8.4 on the `stable` branch and 2.9.0beta5 on the `beta` and `tests-passed` branches, inviting users on sites that use single sign-on could bypass the `must_approve_user...