First published: Thu Oct 06 2022(Updated: )
discourse-chat is a plugin for the Discourse message board which adds chat functionality. In versions prior to 0.9 some places render a chat channel's name and description in an unsafe way, allowing staff members to cause an cross site scripting (XSS) attack by inserting unsafe HTML into them. Version 0.9 has addressed this issue. Users are advised to upgrade. There are no known workarounds for this issue.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Discourse Discourse-chat | <0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-39279 has been classified as a high-severity vulnerability due to its potential for XSS attacks.
To fix CVE-2022-39279, update the Discourse-chat plugin to version 0.9 or later.
CVE-2022-39279 allows for potential cross-site scripting (XSS) attacks, which can lead to data theft or session hijacking.
CVE-2022-39279 affects all versions of Discourse-chat prior to 0.9.
Staff members with access to render chat channel names and descriptions are primarily impacted by CVE-2022-39279.