CVE-2022-41944: Discourse users can see notifications for topics they no longer have access to
Discourse is an open-source discussion platform. In stable versions prior to 2.8.12 and beta or tests-passed versions prior to 2.9.0.beta.13, under certain conditions, a user can see notifications for topics they no longer have access to. If there is sensitive information in the topic title, it will therefore have been exposed. This issue is patched in stable version 2.8.12, beta version 2.9.0.beta13, and tests-passed version 2.9.0.beta13. There are no workarounds available.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.8.12 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.9.0.beta13
Event History
Frequently Asked Questions
What is the severity of CVE-2022-41944?
CVE-2022-41944 has a moderate severity as it allows users to see notifications for topics they no longer have access to, potentially exposing sensitive information.
How do I fix CVE-2022-41944?
To fix CVE-2022-41944, update your Discourse application to version 2.8.12 or newer, or to version 2.9.0.beta13 or newer.
What versions of Discourse are affected by CVE-2022-41944?
CVE-2022-41944 affects Discourse versions prior to 2.8.12 and beta versions before 2.9.0.beta13.
What kind of information can be exposed by CVE-2022-41944?
CVE-2022-41944 can potentially expose sensitive information contained in topics that users are no longer permitted to access.
Is there a workaround for CVE-2022-41944 if I can't update my Discourse version?
There is no specified workaround for CVE-2022-41944; upgrading to a patched version is the recommended action.