SB2023010510 - Multiple vulnerabilities in Discourse



SB2023010510 - Multiple vulnerabilities in Discourse

Published: January 5, 2023 Updated: July 1, 2026

Security Bulletin ID SB2023010510
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 vulnerabilities.


1) Improper access control (CVE-ID: CVE-2022-46177)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote administrator to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to the password reset link can lead to in account takeover if user changes to a new email.


2) Improper access control (CVE-ID: CVE-2022-46159)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to create an unlisted topic.

The vulnerability exists due to improper access control in topic creation functionality when handling requests to create topics. A remote user can submit a request to create an unlisted topic to create an unlisted topic.

These topics are not readily available to other users and can consume unnecessary site resources.


Remediation

Install update from vendor's website.