CVE-2022-21684
Discourse is an open source discussion platform. Versions prior to 2.7.13 in `stable`, 2.8.0.beta11 in `beta`, and 2.8.0.beta11 in `tests-passed` allow some users to log in to a community before they should be able to do so. A user invited via email to a forum with `must_approve_users` enabled is going to be automatically logged in, bypassing the check that does not allow unapproved users to sign in. They will be able to do everything an approved user can do. If they logout, they cannot log back in. This issue is patched in the `stable` version 2.7.13, `beta` version 2.8.0.beta11, and `tests-passed` version 2.8.0.beta11. One may disable invites as a workaround. Administrators can increase `min_trust_level_to_allow_invite` to reduce the attack surface to more trusted users.
Published at
2022-01-13
3 days ago
Modified
2022-01-13
3 days ago
2022
Year
The year of the turtle
https://github.com/discourse/discourse/security/advisories/GHSA-p63q-jp48-h8xh
CONFIRM:https://github.com/discourse/discourse/security/advisories/GHSA-p63q-jp48-h8xh
https://github.com/discourse/discourse/commit/584c6a2e8bc705072b09a9c4b55126d6f8ed4ad2
MISC:https://github.com/discourse/discourse/commit/584c6a2e8bc705072b09a9c4b55126d6f8ed4ad2
https://meta.discourse.org/t/invite-redemption-allowed-user-to-access-forum-before-approval/214328
MISC:https://meta.discourse.org/t/invite-redemption-allowed-user-to-access-forum-before-approval/214328
Vulnerability RAW
{
"Title": {
"_text": "CVE-2022-21684"
},
"Notes": {
"Note": [
{
"_text": "Discourse is an open source discussion platform. Versions prior to 2.7.13 in `stable`, 2.8.0.beta11 in `beta`, and 2.8.0.beta11 in `tests-passed` allow some users to log in to a community before they should be able to do so. A user invited via email to a forum with `must_approve_users` enabled is going to be automatically logged in, bypassing the check that does not allow unapproved users to sign in. They will be able to do everything an approved user can do. If they logout, they cannot log back in. This issue is patched in the `stable` version 2.7.13, `beta` version 2.8.0.beta11, and `tests-passed` version 2.8.0.beta11. One may disable invites as a workaround. Administrators can increase `min_trust_level_to_allow_invite` to reduce the attack surface to more trusted users."
},
{
"_text": "2022-01-13"
},
{
"_text": "2022-01-13"
}
]
},
"CVE": {
"_text": "CVE-2022-21684"
},
"References": {
"Reference": [
{
"URL": {
"_text": "https://github.com/discourse/discourse/security/advisories/GHSA-p63q-jp48-h8xh"
},
"Description": {
"_text": "CONFIRM:https://github.com/discourse/discourse/security/advisories/GHSA-p63q-jp48-h8xh"
}
},
{
"URL": {
"_text": "https://github.com/discourse/discourse/commit/584c6a2e8bc705072b09a9c4b55126d6f8ed4ad2"
},
"Description": {
"_text": "MISC:https://github.com/discourse/discourse/commit/584c6a2e8bc705072b09a9c4b55126d6f8ed4ad2"
}
},
{
"URL": {
"_text": "https://meta.discourse.org/t/invite-redemption-allowed-user-to-access-forum-before-approval/214328"
},
"Description": {
"_text": "MISC:https://meta.discourse.org/t/invite-redemption-allowed-user-to-access-forum-before-approval/214328"
}
}
]
}
}