CVE-2022-39356: Discourse user account takeover via email and invite link
Discourse is a platform for community discussion. Users who receive an invitation link that is not scoped to a single email address can enter any non-admin user's email and gain access to their account when accepting the invitation. All users should upgrade to the latest version. A workaround is temporarily disabling invitations with SiteSetting.maxinvitesperday = 0 or scope them to individual email addresses.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-39356?
CVE-2022-39356 is considered a high-severity vulnerability due to its potential for unauthorized account access.
How do I fix CVE-2022-39356?
To address CVE-2022-39356, users should upgrade to the latest version of Discourse.
Who is affected by CVE-2022-39356?
CVE-2022-39356 affects all users of Discourse versions prior to 2.8.10 and beta versions of 2.9.0.
What does CVE-2022-39356 allow an attacker to do?
CVE-2022-39356 allows an attacker to access the account of any non-admin user by exploiting invitation links not scoped to an email address.
Are there any workarounds for CVE-2022-39356?
There are no specific workarounds for CVE-2022-39356; upgrading to a secure version is the recommended action.