Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-41823 | Discourse is a platform for community discussion. Users who receive an invitation link that is not scoped to a single email address can enter any non-admin user's email and gain access to their account when accepting the invitation. All users should upgrade to the latest version. A workaround is temporarily disabling invitations with `SiteSetting.max_invites_per_day = 0` or scope them to individual email addresses. |
Wed, 23 Apr 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-23T16:41:45.660Z
Reserved: 2022-09-02T00:00:00.000Z
Link: CVE-2022-39356
Updated: 2024-08-03T12:00:44.190Z
Status : Modified
Published: 2022-11-02T17:15:17.520
Modified: 2024-11-21T07:18:06.413
Link: CVE-2022-39356
No data.
OpenCVE Enrichment
No data.
EUVD