SB2023010510 - Multiple vulnerabilities in Discourse
Published: January 5, 2023 Updated: July 1, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 vulnerabilities.
1) Improper access control (CVE-ID: CVE-2022-46177)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote administrator to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the password reset link can lead to in account takeover if user changes to a new email.
2) Improper access control (CVE-ID: CVE-2022-46159)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote user to create an unlisted topic.
The vulnerability exists due to improper access control in topic creation functionality when handling requests to create topics. A remote user can submit a request to create an unlisted topic to create an unlisted topic.
These topics are not readily available to other users and can consume unnecessary site resources.
Remediation
Install update from vendor's website.