CVE-2022-39385: Users erroneously and transparently added to private messages in Discourse
Discourse is the an open source discussion platform. In some rare cases users redeeming an invitation can be added as a participant to several private message topics that they should not be added to. They are not notified of this, it happens transparently in the background. This issue has been resolved in commit a414520742 and will be included in future releases. Users are advised to upgrade. Users are also advised to set SiteSetting.maxinvitesperday to 0 until the patch is installed.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-39385?
CVE-2022-39385 is considered a medium severity vulnerability that may result in unauthorized access to private message topics.
How do I fix CVE-2022-39385?
To fix CVE-2022-39385, users should update Discourse to version 2.9.0 or later.
Who is affected by CVE-2022-39385?
CVE-2022-39385 affects users of Discourse versions prior to 2.8.10 and certain beta releases of 2.9.0.
What type of vulnerability is CVE-2022-39385?
CVE-2022-39385 is a privacy concern, as it allows users to be added to private message topics without their consent.
When was CVE-2022-39385 reported?
CVE-2022-39385 was reported in late 2022 after the discovery of the issue with user invitation redemption.