CVE-2022-36068

Published

Severity

CVSS v3:
4.3 MEDIUM
CVSS v2:
N/A

Description

Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.beta10 on the `beta` and `tests-passed` branches, a moderator can create new and edit existing themes by using the API when they should not be able to do so. The problem is patched in version 2.8.9 on the `stable` branch and version 2.9.0.beta10 on the `beta` and `tests-passed` branches. There are no known workarounds.

References

Configurations

CPE23Version StartVersion EndExact Version
cpe:2.3:a:discourse:discourse:2.9.0:beta1:*:*:*:*:*:*n/an/a2.9.0
cpe:2.3:a:discourse:discourse:2.9.0:beta2:*:*:*:*:*:*n/an/a2.9.0
cpe:2.3:a:discourse:discourse:2.9.0:beta3:*:*:*:*:*:*n/an/a2.9.0
cpe:2.3:a:discourse:discourse:2.9.0:beta4:*:*:*:*:*:*n/an/a2.9.0
cpe:2.3:a:discourse:discourse:2.9.0:beta5:*:*:*:*:*:*n/an/a2.9.0
cpe:2.3:a:discourse:discourse:2.9.0:beta7:*:*:*:*:*:*n/an/a2.9.0
cpe:2.3:a:discourse:discourse:2.9.0:beta8:*:*:*:*:*:*n/an/a2.9.0
cpe:2.3:a:discourse:discourse:2.9.0:beta6:*:*:*:*:*:*n/an/a2.9.0
cpe:2.3:a:discourse:discourse:2.9.0:beta9:*:*:*:*:*:*n/an/a2.9.0
cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*n/a2.8.9*

External Links