SB2022010540 - Multiple vulnerabilities in Discourse



SB2022010540 - Multiple vulnerabilities in Discourse

Published: January 5, 2022 Updated: July 1, 2026

Security Bulletin ID SB2022010540
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 3
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 33% Low 67%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 3 vulnerabilities.


1) Improper access control (CVE-ID: CVE-2022-21684)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to bypass user approval and access the forum with the permissions of an approved user.

The vulnerability exists due to improper access control in the invite redemption flow when redeeming an email invitation on forums with user approval required. A remote user can redeem a valid invitation to bypass user approval and access the forum with the permissions of an approved user.

Only users invited via email are affected, and the access is limited to the initial automatic login session.


2) Improper access control (CVE-ID: CVE-2022-21678)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper access control in user profile page metadata when rendering restricted user profiles. A remote attacker can access a private user's profile page to disclose sensitive information.

The issue exposes profile bio content in meta tags even when the user's profile is set to private.


3) Improper access control (CVE-ID: CVE-2022-21642)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in the composer user suggestions feature when composing a message from a topic. A remote user can compose a message from a topic to disclose sensitive information.

The issue reveals whisper participants.


Remediation

Install update from vendor's website.