#VU65868 Deserialization of Untrusted Data in Discourse - CVE-2022-32224
Published: July 28, 2022
Discourse
Civilized Discourse Construction Kit, Inc.
Description
The vulnerability allows a remote user to execute arbitrary code on the target system.
The vulnerability exists due to insecure input validation when processing serialized data in columns in active records. A remote privileged user write access to the database (e.g. via the restore pipeline) can create a specially crafted column and execute arbitrary code on the system during backup restoration.