CVE-2022-23548: Medium severity discourse vulnerability
Discourse is an option source discussion platform. Prior to version 2.8.14 on the stable branch and version 2.9.0.beta16 on the beta and tests-passed branches, parsing posts can be susceptible to regular expression denial of service (ReDoS) attacks. This issue is patched in versions 2.8.14 and 2.9.0.beta16. There are no known workarounds.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-23548?
CVE-2022-23548 is a vulnerability in the Discourse discussion platform that can be exploited by regular expression denial of service (ReDoS) attacks.
How severe is CVE-2022-23548?
CVE-2022-23548 has a severity rating of 6.5, which is considered medium.
Which versions of Discourse are affected by CVE-2022-23548?
Versions up to 2.8.14 on the 'stable' branch and versions 2.9.0.beta16 on the 'beta' and 'tests-passed' branches of Discourse are affected.
How can I fix CVE-2022-23548?
You can fix CVE-2022-23548 by updating your Discourse installation to version 2.8.14 for the 'stable' branch and version 2.9.0.beta16 for the 'beta' and 'tests-passed' branches.
Where can I find more information about CVE-2022-23548?
You can find more information about CVE-2022-23548 in the following references: [GitHub Pull Request](https://github.com/discourse/discourse/pull/19737) and [GitHub Security Advisory](https://github.com/discourse/discourse/security/advisories/GHSA-7rw2-f4x7-7pxf).