CVE-2022-36066: Discourse vulnerable to RCE via admins uploading maliciously zipped file
Discourse is an open source discussion platform. In versions prior to 2.8.9 on the stable branch and prior to 2.9.0.beta10 on the beta and tests-passed branches, admins can upload a maliciously crafted Zip or Gzip Tar archive to write files at arbitrary locations and trigger remote code execution. The problem is patched in version 2.8.9 on the stable branch and version 2.9.0.beta10 on the beta and tests-passed branches. There are no known workarounds.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-36066?
CVE-2022-36066 has a medium severity rating that could potentially allow an attacker to write files at arbitrary locations.
How do I fix CVE-2022-36066?
To fix CVE-2022-36066, upgrade Discourse to version 2.8.9 or later on the stable branch or to version 2.9.0.beta10 or later on the beta and tests-passed branches.
Which versions of Discourse are affected by CVE-2022-36066?
CVE-2022-36066 affects Discourse versions prior to 2.8.9 on the stable branch and prior to 2.9.0.beta10 on the beta and tests-passed branches.
What do I need to be aware of regarding file uploads in CVE-2022-36066?
CVE-2022-36066 allows admins to upload maliciously crafted Zip or Gzip Tar archives that could lead to severe consequences.
Is there a patch available for CVE-2022-36066?
Yes, a patch for CVE-2022-36066 is included in the updates for versions 2.8.9 and 2.9.0.beta10 or later.