CVE-2022-39385
- EPSS 0.5%
- Veröffentlicht 14.11.2022 21:15:15
- Zuletzt bearbeitet 21.11.2024 07:18:11
Discourse is the an open source discussion platform. In some rare cases users redeeming an invitation can be added as a participant to several private message topics that they should not be added to. They are not notified of this, it happens transpar...
CVE-2022-39241
- EPSS 0.52%
- Veröffentlicht 02.11.2022 17:15:17
- Zuletzt bearbeitet 21.11.2024 07:17:51
Discourse is a platform for community discussion. A malicious admin could use this vulnerability to perform port enumeration on the local host or other hosts on the internal network, as well as against hosts on the Internet. Latest `stable`, `beta`, ...
CVE-2022-39356
- EPSS 0.56%
- Veröffentlicht 02.11.2022 17:15:17
- Zuletzt bearbeitet 21.11.2024 07:18:06
Discourse is a platform for community discussion. Users who receive an invitation link that is not scoped to a single email address can enter any non-admin user's email and gain access to their account when accepting the invitation. All users should ...
CVE-2022-39378
- EPSS 0.48%
- Veröffentlicht 02.11.2022 17:15:17
- Zuletzt bearbeitet 21.11.2024 07:18:10
Discourse is a platform for community discussion. Under certain conditions, a user badge may have been awarded based on a user's activity in a topic with restricted access. Before this vulnerability was disclosed, the topic title of the topic associa...
CVE-2022-39232
- EPSS 0.95%
- Veröffentlicht 29.09.2022 21:15:11
- Zuletzt bearbeitet 21.11.2024 07:17:50
Discourse is an open source discussion platform. Starting with version 2.9.0.beta5 and prior to version 2.9.0.beta10, an incomplete quote can generate a JavaScript error which will crash the current page in the browser in some cases. Version 2.9.0.be...
CVE-2022-36068
- EPSS 0.72%
- Veröffentlicht 29.09.2022 20:15:13
- Zuletzt bearbeitet 21.11.2024 07:12:18
Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.beta10 on the `beta` and `tests-passed` branches, a moderator can create new and edit existing themes by using the API when they sho...
CVE-2022-39226
- EPSS 0.78%
- Veröffentlicht 29.09.2022 20:15:13
- Zuletzt bearbeitet 21.11.2024 07:17:49
Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.beta10 on the `beta` and `tests-passed` branches, a malicious actor can add large payloads of text into the Location and Website fie...
CVE-2022-36066
- EPSS 1.57%
- Veröffentlicht 29.09.2022 20:15:09
- Zuletzt bearbeitet 21.11.2024 07:12:18
Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.beta10 on the `beta` and `tests-passed` branches, admins can upload a maliciously crafted Zip or Gzip Tar archive to write files at ...
CVE-2022-37458
- EPSS 1.07%
- Veröffentlicht 02.09.2022 12:15:11
- Zuletzt bearbeitet 21.11.2024 07:15:01
Discourse through 2.8.7 allows admins to send invitations to arbitrary email addresses at an unlimited rate.
CVE-2022-31182
- EPSS 0.64%
- Veröffentlicht 01.08.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 07:04:04
Discourse is the an open source discussion platform. In affected versions a maliciously crafted request for static assets could cause error responses to be cached by Discourse's default NGINX proxy configuration. A corrected NGINX configuration is in...