SB2022062130 - Improper access control in Discourse
Published: June 21, 2022 Updated: July 1, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper access control (CVE-ID: CVE-2022-31096)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote user to bypass invite email or email domain restrictions and gain unauthorized access to restricted content.
The vulnerability exists due to improper access control in the invite redemption mechanism when redeeming an invite. A remote user can redeem an invite with an email address that does not match the invite restrictions to bypass invite email or email domain restrictions and gain unauthorized access to restricted content.
If the invite is configured to add the accepting user to restricted groups, successful exploitation may result in unauthorized membership in those groups.
Remediation
Install update from vendor's website.