HIGH
Discourse moderators can edit themes via the API
Published Sep 29, 2022
7.2
HIGHCVSS 3.1
EPSS 0.89%
Description
Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.beta10 on the `beta` and `tests-passed` branches, a moderator can create new and edit existing themes by using the API when they should not be able to do so. The problem is patched in version 2.8.9 on the `stable` branch and version 2.9.0.beta10 on the `beta` and `tests-passed` branches. There are no known workarounds.
Affected products
-
- Version < 2.8.9StatusaffectedConstraints-
- Version >= 2.9.0.beta0, < 2.9.0.beta10StatusaffectedConstraints-
- Version
OR
- < 2.8.9
- 2.9.0
- 2.9.0
- 2.9.0
- 2.9.0
- 2.9.0
- 2.9.0
- 2.9.0
- 2.9.0
- 2.9.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://github.com/discourse/discourse/commit/ae1e536e83940d58f1c79b835c75c249121c46b6 x_refsource_MISCPatchThird Party Advisory
- https://github.com/discourse/discourse/pull/18418 x_refsource_MISCPatchThird Party Advisory
- https://github.com/discourse/discourse/security/advisories/GHSA-6crr-3662-263q x_refsource_CONFIRMThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/discourse/discourse/commit/ae1e536e83940d58f1c79b835c75c249121c46b6 | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/discourse/discourse/pull/18418 | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/discourse/discourse/security/advisories/GHSA-6crr-3662-263q | x_refsource_CONFIRMThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Sep 29, 2022
Updated Apr 23, 2025
Reserved Jul 15, 2022
Link CVE-2022-36068
CISA Vulnrichment
Updated Apr 23, 2025