« Volver al listado

CVE-2022-23549

Estado: ModificadaMedia (6.5)—

Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 2.9.0.beta16 on the `beta` and `tests-passed` branches, users can create posts with raw body longer than the `max_length` site setting by including html comments that are not counted toward the character limit. This issue is patched in versions 2.8.14 and 2.9.0.beta16. There are no known workarounds.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-23549",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-23549",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-03-10T21:00:30.999857Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.7,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.1
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "discourse",
          "product": "discourse",
          "versions": [
            {
              "status": "affected",
              "version": "2.8.14",
              "lessThan": "2.8.14",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "2.9.0.beta0",
              "versionType": "custom",
              "lessThanOrEqual": "2.9.0.beta0"
            },
            {
              "status": "affected",
              "version": "2.9.0.beta16",
              "lessThan": "2.9.0.beta16",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2023-01-05T19:15:09.500",
  "references": [
    {
      "url": "https://github.com/discourse/discourse/commit/bf6b08670a927cc80bb090b7a2e710b4b554e6a8",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/discourse/discourse/security/advisories/GHSA-p47g-v5wr-p4xp",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/discourse/discourse/commit/bf6b08670a927cc80bb090b7a2e710b4b554e6a8",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/discourse/discourse/security/advisories/GHSA-p47g-v5wr-p4xp",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 2.9.0.beta16 on the `beta` and `tests-passed` branches, users can create posts with raw body longer than the `max_length` site setting by including html comments that are not counted toward the character limit. This issue is patched in versions 2.8.14 and 2.9.0.beta16. There are no known workarounds."
    },
    {
      "lang": "es",
      "value": "Discourse es una plataforma de discusión de fuentes de opciones. Antes de la versión 2.8.14 en la rama `stable` y la versión 2.9.0.beta16 en las ramas `beta` y `tests-passed`, los usuarios podían crear publicaciones con un cuerpo sin formato más largo que la configuración del sitio `max_length` al incluir html comentarios que no cuentan para el límite de caracteres. Este problema se solucionó en las versiones 2.8.14 y 2.9.0.beta16. No se conocen workarounds."
    }
  ],
  "lastModified": "2026-06-17T04:30:20.250",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9C13BCBA-EF34-4F4B-9F4A-33392EB45196",
              "versionEndExcluding": "2.8.14"
            },
            {
              "criteria": "cpe:2.3:a:discourse:discourse:2.9.0:beta1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B3803EF9-A296-42B7-887F-93C5E68E94C4"
            },
            {
              "criteria": "cpe:2.3:a:discourse:discourse:2.9.0:beta10:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "35BAC488-3622-4B0B-B8EA-879E8C68E8CF"
            },
            {
              "criteria": "cpe:2.3:a:discourse:discourse:2.9.0:beta11:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "406A23B4-B971-4DC8-A132-EE9854FE8546"
            },
            {
              "criteria": "cpe:2.3:a:discourse:discourse:2.9.0:beta12:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1DD3C47F-E49F-4E19-9EA7-A322C4CFD541"
            },
            {
              "criteria": "cpe:2.3:a:discourse:discourse:2.9.0:beta13:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E924AC08-6978-4DFF-B616-9E3E9D6FBE1B"
            },
            {
              "criteria": "cpe:2.3:a:discourse:discourse:2.9.0:beta14:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B5A3C7FB-B3B6-45F0-AD7D-062A50490AD7"
            },
            {
              "criteria": "cpe:2.3:a:discourse:discourse:2.9.0:beta2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8BA3D313-3C11-43E2-A47D-CBB532D1B6F8"
            },
            {
              "criteria": "cpe:2.3:a:discourse:discourse:2.9.0:beta3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6F42673E-65F3-4807-9484-20CB747420FB"
            },
            {
              "criteria": "cpe:2.3:a:discourse:discourse:2.9.0:beta4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0B91D023-FCE5-4866-AD8B-BBB675763104"
            },
            {
              "criteria": "cpe:2.3:a:discourse:discourse:2.9.0:beta5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0086484D-0164-449C-8AAE-BE7479CB9706"
            },
            {
              "criteria": "cpe:2.3:a:discourse:discourse:2.9.0:beta6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F9D1B031-96C7-44C0-A0A0-F67ABE55C93C"
            },
            {
              "criteria": "cpe:2.3:a:discourse:discourse:2.9.0:beta7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "750D2AD9-35E7-4AC7-9C22-AA90DAA34F3F"
            },
            {
              "criteria": "cpe:2.3:a:discourse:discourse:2.9.0:beta8:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B68E308A-BDAB-4614-A563-4460F7996CBE"
            },
            {
              "criteria": "cpe:2.3:a:discourse:discourse:3.0.0:beta15:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F62275F8-11E9-4D94-8F2E-F83905F65031"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}