← Back

CVE-2023-22454

nvd nist
Published: Jan 5, 2023Modified: Nov 21, 2024

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 3.0.0.beta16 on the `beta` and `tests-passed` branches, pending post titles can be used for cross-site scripting attacks. Pending posts can be created by unprivileged users when a category has the "require moderator approval of all new topics" setting set. This vulnerability can lead to a full XSS on sites which have modified or disabled Discourse’s default Content Security Policy. A patch is available in versions 2.8.14 and 3.0.0.beta16.

Affected (206)

Products: Discourse: Discourse
1 product
Discourse
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 2.8.14
Configuration B
205 vulnerable
Vulnerable SoftwareAffected Versions
Discourse
Version 1.1.0 beta1
Version 1.1.0 beta2
Version 1.1.0 beta3
Version 1.1.0 beta4
Version 1.1.0 beta5
Version 1.1.0 beta6
Version 1.1.0 beta6b
Version 1.1.0 beta7
Version 1.1.0 beta8
Version 1.2.0 beta1
Version 1.2.0 beta2
Version 1.2.0 beta3
Version 1.2.0 beta4
Version 1.2.0 beta5
Version 1.2.0 beta6
Version 1.2.0 beta7
Version 1.2.0 beta8
Version 1.2.0 beta9
Version 1.3.0 beta10
Version 1.3.0 beta11
Version 1.3.0 beta1
Version 1.3.0 beta2
Version 1.3.0 beta3
Version 1.3.0 beta4
Version 1.3.0 beta5
Version 1.3.0 beta6
Version 1.3.0 beta7
Version 1.3.0 beta8
Version 1.3.0 beta9
Version 1.4.0 beta10
Version 1.4.0 beta11
Version 1.4.0 beta12
Version 1.4.0 beta1
Version 1.4.0 beta2
Version 1.4.0 beta3
Version 1.4.0 beta4
Version 1.4.0 beta5
Version 1.4.0 beta6
Version 1.4.0 beta7
Version 1.4.0 beta8
Version 1.4.0 beta9
Version 1.5.0 beta10
Version 1.5.0 beta11
Version 1.5.0 beta12
Version 1.5.0 beta13
Version 1.5.0 beta13b
Version 1.5.0 beta14
Version 1.5.0 beta1
Version 1.5.0 beta2
Version 1.5.0 beta3
Version 1.5.0 beta4
Version 1.5.0 beta5
Version 1.5.0 beta6
Version 1.5.0 beta7
Version 1.5.0 beta8
Version 1.5.0 beta9
Version 1.6.0 beta10
Version 1.6.0 beta11
Version 1.6.0 beta12
Version 1.6.0 beta1
Version 1.6.0 beta2
Version 1.6.0 beta3
Version 1.6.0 beta4
Version 1.6.0 beta5
Version 1.6.0 beta6
Version 1.6.0 beta7
Version 1.6.0 beta8
Version 1.6.0 beta9
Version 1.7.0 beta10
Version 1.7.0 beta11
Version 1.7.0 beta1
Version 1.7.0 beta2
Version 1.7.0 beta3
Version 1.7.0 beta4
Version 1.7.0 beta5
Version 1.7.0 beta6
Version 1.7.0 beta7
Version 1.7.0 beta8
Version 1.7.0 beta9
Version 1.8.0 beta10
Version 1.8.0 beta11
Version 1.8.0 beta12
Version 1.8.0 beta13
Version 1.8.0 beta1
Version 1.8.0 beta2
Version 1.8.0 beta3
Version 1.8.0 beta4
Version 1.8.0 beta5
Version 1.8.0 beta6
Version 1.8.0 beta7
Version 1.8.0 beta8
Version 1.8.0 beta9
Version 1.9.0 beta10
Version 1.9.0 beta11
Version 1.9.0 beta12
Version 1.9.0 beta13
Version 1.9.0 beta14
Version 1.9.0 beta15
Version 1.9.0 beta16
Version 1.9.0 beta17
Version 1.9.0 beta1
Version 1.9.0 beta2
Version 1.9.0 beta3
Version 1.9.0 beta4
Version 1.9.0 beta5
Version 1.9.0 beta6
Version 1.9.0 beta7
Version 1.9.0 beta8
Version 1.9.0 beta9
Version 2.0.0 beta10
Version 2.0.0 beta1
Version 2.0.0 beta2
Version 2.0.0 beta3
Version 2.0.0 beta4
Version 2.0.0 beta5
Version 2.0.0 beta6
Version 2.0.0 beta7
Version 2.0.0 beta8
Version 2.0.0 beta9
Version 2.1.0 beta1
Version 2.1.0 beta2
Version 2.1.0 beta3
Version 2.1.0 beta4
Version 2.1.0 beta5
Version 2.1.0 beta6
Version 2.2.0 beta10
Version 2.2.0 beta1
Version 2.2.0 beta2
Version 2.2.0 beta3
Version 2.2.0 beta4
Version 2.2.0 beta5
Version 2.2.0 beta6
Version 2.2.0 beta7
Version 2.2.0 beta8
Version 2.2.0 beta9
Version 2.3.0 beta10
Version 2.3.0 beta11
Version 2.3.0 beta1
Version 2.3.0 beta2
Version 2.3.0 beta3
Version 2.3.0 beta4
Version 2.3.0 beta5
Version 2.3.0 beta6
Version 2.3.0 beta7
Version 2.3.0 beta8
Version 2.3.0 beta9
Version 2.4.0 beta10
Version 2.4.0 beta11
Version 2.4.0 beta1
Version 2.4.0 beta2
Version 2.4.0 beta3
Version 2.4.0 beta4
Version 2.4.0 beta5
Version 2.4.0 beta6
Version 2.4.0 beta7
Version 2.4.0 beta8
Version 2.4.0 beta9
Version 2.5.0 beta1
Version 2.5.0 beta2
Version 2.5.0 beta3
Version 2.5.0 beta4
Version 2.5.0 beta5
Version 2.5.0 beta6
Version 2.5.0 beta7
Version 2.6.0 beta1
Version 2.6.0 beta2
Version 2.6.0 beta3
Version 2.6.0 beta4
Version 2.6.0 beta5
Version 2.6.0 beta6
Version 2.7.0 beta1
Version 2.7.0 beta2
Version 2.7.0 beta3
Version 2.7.0 beta4
Version 2.7.0 beta5
Version 2.7.0 beta6
Version 2.7.0 beta7
Version 2.7.0 beta8
Version 2.7.0 beta9
Version 2.8.0 beta10
Version 2.8.0 beta11
Version 2.8.0 beta1
Version 2.8.0 beta2
Version 2.8.0 beta3
Version 2.8.0 beta4
Version 2.8.0 beta5
Version 2.8.0 beta6
Version 2.8.0 beta7
Version 2.8.0 beta8
Version 2.8.0 beta9
Version 2.9.0 beta10
Version 2.9.0 beta11
Version 2.9.0 beta12
Version 2.9.0 beta13
Version 2.9.0 beta14
Version 2.9.0 beta1
Version 2.9.0 beta2
Version 2.9.0 beta3
Version 2.9.0 beta4
Version 2.9.0 beta5
Version 2.9.0 beta6
Version 2.9.0 beta7
Version 2.9.0 beta8
Version 2.9.0 beta9
Version 3.0.0 beta15

References (4)

Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.