CVE-2022-39226 Information
Sep 30, 2022
cve
Description
Discourse is an open source discussion platform. In versions prior to 2.8.9 on the stable branch and prior to 2.9.0.beta10 on the beta and tests-passed branches a malicious actor can add large payloads of text into the Location and Website fields of a user profile which causes issues for other users when loading that profile. A fix to limit the length of user input for these fields is included in version 2.8.9 on the stable branch and version 2.9.0.beta10 on the beta and tests-passed branches. There are no known workarounds.
Reference
https://github.com/discourse/discourse/security/advisories/GHSA-jw3q-xg5g-qjrw https://github.com/discourse/discourse/commit/e69f7d2fd9c977dedbdb17f6813651e2a45bfb71 https://github.com/discourse/discourse/pull/18302
Share on: