SB2022062130 - Improper access control in Discourse



SB2022062130 - Improper access control in Discourse

Published: June 21, 2022 Updated: July 1, 2026

Security Bulletin ID SB2022062130
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper access control (CVE-ID: CVE-2022-31096)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to bypass invite email or email domain restrictions and gain unauthorized access to restricted content.

The vulnerability exists due to improper access control in the invite redemption mechanism when redeeming an invite. A remote user can redeem an invite with an email address that does not match the invite restrictions to bypass invite email or email domain restrictions and gain unauthorized access to restricted content.

If the invite is configured to add the accepting user to restricted groups, successful exploitation may result in unauthorized membership in those groups.


Remediation

Install update from vendor's website.