CVE-2022-46159
02.12.2022, 15:15
Discourse is an open-source discussion platform. In version 2.8.13 and prior on the `stable` branch and version 2.9.0.beta14 and prior on the `beta` and `tests-passed` branches, any authenticated user can create an unlisted topic. These topics, which are not readily available to other users, can take up unnecessary site resources. A patch for this issue is available in the `main` branch of Discourse. There are no known workarounds available.Enginsight
| Vendor | Product | Version |
|---|---|---|
| discourse | discourse | 𝑥 ≤ 2.8.13 |
| discourse | discourse | 2.9.0:beta1 |
| discourse | discourse | 2.9.0:beta10 |
| discourse | discourse | 2.9.0:beta11 |
| discourse | discourse | 2.9.0:beta12 |
| discourse | discourse | 2.9.0:beta13 |
| discourse | discourse | 2.9.0:beta14 |
| discourse | discourse | 2.9.0:beta2 |
| discourse | discourse | 2.9.0:beta3 |
| discourse | discourse | 2.9.0:beta4 |
| discourse | discourse | 2.9.0:beta5 |
| discourse | discourse | 2.9.0:beta6 |
| discourse | discourse | 2.9.0:beta7 |
| discourse | discourse | 2.9.0:beta8 |
𝑥
= Vulnerable software versions
References