CVE-2022-46159: Any authenticated Discourse user can create an unlisted topic
Discourse is an open-source discussion platform. In version 2.8.13 and prior on the stable branch and version 2.9.0.beta14 and prior on the beta and tests-passed branches, any authenticated user can create an unlisted topic. These topics, which are not readily available to other users, can take up unnecessary site resources. A patch for this issue is available in the main branch of Discourse. There are no known workarounds available.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-46159?
The severity of CVE-2022-46159 is categorized as moderate, affecting privacy and access control.
How do I fix CVE-2022-46159?
To fix CVE-2022-46159, upgrade to Discourse version 2.8.14 or 2.9.0.beta15 or later.
Who is affected by CVE-2022-46159?
Any authenticated user on Discourse versions 2.8.13 and prior on the stable branch or 2.9.0.beta14 and prior on beta branches is affected by CVE-2022-46159.
What type of attack does CVE-2022-46159 enable?
CVE-2022-46159 allows authenticated users to create unlisted topics that can bypass standard visibility settings.
When was CVE-2022-46159 disclosed?
CVE-2022-46159 was disclosed on December 7, 2022.