#VU65868 Deserialization of Untrusted Data in Discourse - CVE-2022-32224 

 

#VU65868 Deserialization of Untrusted Data in Discourse - CVE-2022-32224

Published: July 28, 2022


Vulnerability identifier: #VU65868
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2022-32224
CWE-ID: CWE-502
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Discourse
Software vendor:
Civilized Discourse Construction Kit, Inc.

Description

The vulnerability allows a remote user to execute arbitrary code on the target system.

The vulnerability exists due to insecure input validation when processing serialized data in columns in active records. A remote privileged user write access to the database (e.g. via the restore pipeline) can create a specially crafted column and execute arbitrary code on the system during backup restoration.


Remediation

Install updates from vendor's website.

External links