CVE-2022-39385
Users erroneously and transparently added to private messages in Discourse
6.5
MEDIUM
CVSS 3.1
EPSS 0.26%
Description
Discourse is the an open source discussion platform. In some rare cases users redeeming an invitation can be added as a participant to several private message topics that they should not be added to. They are not notified of this, it happens transparently in the background. This issue has been resolved in commit `a414520742` and will be included in future releases. Users are advised to upgrade. Users are also advised to set `SiteSetting.max_invites_per_day` to 0 until the patch is installed.
How to fix CVE-2022-39385
To remediate CVE-2022-39385, upgrade the affected package to a fixed version below.
- —upgrade to 2.8.10 or later
Is CVE-2022-39385 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.8.10
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |