2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2022-46159" ,
"sourceIdentifier" : "security-advisories@github.com" ,
"published" : "2022-12-02T15:15:10.090" ,
2024-12-08 03:06:42 +00:00
"lastModified" : "2024-11-21T07:30:13.710" ,
2023-11-07 21:03:21 +00:00
"vulnStatus" : "Modified" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
2023-11-07 21:03:21 +00:00
"value" : "Discourse is an open-source discussion platform. In version 2.8.13 and prior on the `stable` branch and version 2.9.0.beta14 and prior on the `beta` and `tests-passed` branches, any authenticated user can create an unlisted topic. These topics, which are not readily available to other users, can take up unnecessary site resources. A patch for this issue is available in the `main` branch of Discourse. There are no known workarounds available.\n"
2024-04-04 08:46:00 +00:00
} ,
{
"lang" : "es" ,
"value" : "Discourse es una plataforma de discusi\u00f3n de c\u00f3digo abierto. En la versi\u00f3n 2.8.13 y anteriores en la rama `stable` y en la versi\u00f3n 2.9.0.beta14 y anteriores en las ramas `beta` y `tests-passed`, cualquier usuario autenticado puede crear un tema no listado. Estos temas, que no est\u00e1n disponibles para otros usuarios, pueden consumir recursos innecesarios del sitio. Hay un parche para este problema disponible en la rama \"principal\" de Discourse. No se conocen workarounds disponibles."
2023-04-24 12:24:31 +02:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
2024-12-08 03:06:42 +00:00
"source" : "security-advisories@github.com" ,
"type" : "Secondary" ,
2023-04-24 12:24:31 +02:00
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 4.3 ,
"baseSeverity" : "MEDIUM" ,
2023-04-24 12:24:31 +02:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "NONE" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "LOW"
2023-04-24 12:24:31 +02:00
} ,
"exploitabilityScore" : 2.8 ,
"impactScore" : 1.4
} ,
{
2024-12-08 03:06:42 +00:00
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
2023-04-24 12:24:31 +02:00
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 4.3 ,
"baseSeverity" : "MEDIUM" ,
2023-04-24 12:24:31 +02:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "NONE" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "LOW"
2023-04-24 12:24:31 +02:00
} ,
"exploitabilityScore" : 2.8 ,
"impactScore" : 1.4
}
]
} ,
"weaknesses" : [
{
2024-04-04 08:46:00 +00:00
"source" : "security-advisories@github.com" ,
2024-12-15 03:03:56 +00:00
"type" : "Primary" ,
2023-04-24 12:24:31 +02:00
"description" : [
{
"lang" : "en" ,
"value" : "CWE-770"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "2.8.13" ,
"matchCriteriaId" : "F0A7BB8C-9904-42B5-8D91-0275CCA5D74F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:discourse:discourse:2.9.0:beta1:*:*:*:*:*:*" ,
"matchCriteriaId" : "B3803EF9-A296-42B7-887F-93C5E68E94C4"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:discourse:discourse:2.9.0:beta10:*:*:*:*:*:*" ,
"matchCriteriaId" : "35BAC488-3622-4B0B-B8EA-879E8C68E8CF"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:discourse:discourse:2.9.0:beta11:*:*:*:*:*:*" ,
"matchCriteriaId" : "406A23B4-B971-4DC8-A132-EE9854FE8546"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:discourse:discourse:2.9.0:beta12:*:*:*:*:*:*" ,
"matchCriteriaId" : "1DD3C47F-E49F-4E19-9EA7-A322C4CFD541"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:discourse:discourse:2.9.0:beta13:*:*:*:*:*:*" ,
"matchCriteriaId" : "E924AC08-6978-4DFF-B616-9E3E9D6FBE1B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:discourse:discourse:2.9.0:beta14:*:*:*:*:*:*" ,
"matchCriteriaId" : "B5A3C7FB-B3B6-45F0-AD7D-062A50490AD7"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:discourse:discourse:2.9.0:beta2:*:*:*:*:*:*" ,
"matchCriteriaId" : "8BA3D313-3C11-43E2-A47D-CBB532D1B6F8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:discourse:discourse:2.9.0:beta3:*:*:*:*:*:*" ,
"matchCriteriaId" : "6F42673E-65F3-4807-9484-20CB747420FB"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:discourse:discourse:2.9.0:beta4:*:*:*:*:*:*" ,
"matchCriteriaId" : "0B91D023-FCE5-4866-AD8B-BBB675763104"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:discourse:discourse:2.9.0:beta5:*:*:*:*:*:*" ,
"matchCriteriaId" : "0086484D-0164-449C-8AAE-BE7479CB9706"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:discourse:discourse:2.9.0:beta6:*:*:*:*:*:*" ,
"matchCriteriaId" : "F9D1B031-96C7-44C0-A0A0-F67ABE55C93C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:discourse:discourse:2.9.0:beta7:*:*:*:*:*:*" ,
"matchCriteriaId" : "750D2AD9-35E7-4AC7-9C22-AA90DAA34F3F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:discourse:discourse:2.9.0:beta8:*:*:*:*:*:*" ,
"matchCriteriaId" : "B68E308A-BDAB-4614-A563-4460F7996CBE"
}
]
}
]
}
] ,
"references" : [
{
"url" : "https://github.com/discourse/discourse/commit/0ce38bd7bce862db251b882613ab7053ca777382" ,
"source" : "security-advisories@github.com" ,
"tags" : [
"Patch" ,
"Third Party Advisory"
]
} ,
{
"url" : "https://github.com/discourse/discourse/security/advisories/GHSA-qf99-xpx6-hgxp" ,
"source" : "security-advisories@github.com" ,
"tags" : [
"Third Party Advisory"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://github.com/discourse/discourse/commit/0ce38bd7bce862db251b882613ab7053ca777382" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Patch" ,
"Third Party Advisory"
]
} ,
{
"url" : "https://github.com/discourse/discourse/security/advisories/GHSA-qf99-xpx6-hgxp" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Third Party Advisory"
]
2023-04-24 12:24:31 +02:00
}
]
}