CVE-2023-31142: Discourse's general category permissions could be set back to default
Discourse is an open source discussion platform. Prior to version 3.0.4 of the stable branch and version 3.1.0.beta5 of the beta and tests-passed branches, if a site has modified their general category permissions, they could be set back to the default. This issue is patched in version 3.0.4 of the stable branch and version 3.1.0.beta5 of the beta and tests-passed branches. A workaround, only if you are modifying the general category permissions, is to use a new category for the same purpose.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-31142?
The severity of CVE-2023-31142 is medium with a CVSS score of 5.3.
How can I fix the vulnerability CVE-2023-31142?
To fix the vulnerability CVE-2023-31142, update your Discourse platform to version 3.0.4 or higher.
What is the affected software version of CVE-2023-31142?
The affected software version of CVE-2023-31142 is Discourse version 3.0.4 and below.
Is there a patch available for CVE-2023-31142?
Yes, the issue is patched in version 3.0.4 of the Discourse platform.
Where can I find more information about CVE-2023-31142?
You can find more information about CVE-2023-31142 in the GitHub Security Advisory GHSA-286w-97m2-78x2.