SB2022010540 - Multiple vulnerabilities in Discourse
Published: January 5, 2022 Updated: July 1, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 vulnerabilities.
1) Improper access control (CVE-ID: CVE-2022-21684)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote user to bypass user approval and access the forum with the permissions of an approved user.
The vulnerability exists due to improper access control in the invite redemption flow when redeeming an email invitation on forums with user approval required. A remote user can redeem a valid invitation to bypass user approval and access the forum with the permissions of an approved user.
Only users invited via email are affected, and the access is limited to the initial automatic login session.
2) Improper access control (CVE-ID: CVE-2022-21678)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in user profile page metadata when rendering restricted user profiles. A remote attacker can access a private user's profile page to disclose sensitive information.
The issue exposes profile bio content in meta tags even when the user's profile is set to private.
3) Improper access control (CVE-ID: CVE-2022-21642)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the composer user suggestions feature when composing a message from a topic. A remote user can compose a message from a topic to disclose sensitive information.
The issue reveals whisper participants.
Remediation
Install update from vendor's website.
References
- https://github.com/discourse/discourse/security/advisories/GHSA-p63q-jp48-h8xh
- https://github.com/discourse/discourse/commit/584c6a2e8bc705072b09a9c4b55126d6f8ed4ad2
- https://github.com/discourse/discourse/security/advisories/GHSA-jwww-46gv-564m
- https://github.com/discourse/discourse/commit/5e2e178fcfb490c37b9f8bb9f737185441b1d6de
- https://github.com/discourse/discourse/security/advisories/GHSA-mx3h-vc7w-r9c6
- https://github.com/discourse/discourse/commit/702685b6a06ae45a544fc702027f1e4573d94aaa