« Volver al listado

CVE-2025-22601

Estado: AnalizadaBaja (3.1)—

Discourse is an open source platform for community discussion. In affected versions an attacker can trick a target user to make changes to their own username via carefully crafted link using the `activate-account` route. This problem has been patched in the latest version of Discourse. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-22601",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-22601",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-02-11T21:32:06.142468Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 3.1,
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 1.6
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "discourse",
          "product": "discourse",
          "versions": [
            {
              "status": "affected",
              "version": "beta: <= 3.4.0.beta3"
            },
            {
              "status": "affected",
              "version": "tests-passed: <= 3.4.0.beta3"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-02-04T21:15:27.800",
  "references": [
    {
      "url": "https://github.com/discourse/discourse/security/advisories/GHSA-gvpp-v7mp-wxxw",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Discourse is an open source platform for community discussion. In affected versions an attacker can trick a target user to make changes to their own username via carefully crafted link using the `activate-account` route. This problem has been patched in the latest version of Discourse. Users are advised to upgrade. There are no known workarounds for this vulnerability."
    },
    {
      "lang": "es",
      "value": "Discourse es una plataforma de código abierto para debates comunitarios. En las versiones afectadas, un atacante puede engañar a un usuario objetivo para que realice cambios en su propio nombre de usuario a través de un enlace manipulado cuidadosamente seleccionado utilizando la ruta `activate-account`. Este problema ha sido corregido en la última versión de Discourse. Se recomienda a los usuarios que actualicen la versión. No se conocen workarounds para esta vulnerabilidad."
    }
  ],
  "lastModified": "2026-06-17T08:48:36.563",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:discourse:discourse:*:*:*:*:beta:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B70F4653-EB23-49AB-AF71-C39E5B6D5E5F",
              "versionEndExcluding": "3.4.0"
            },
            {
              "criteria": "cpe:2.3:a:discourse:discourse:3.4.0:beta1:*:*:beta:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AF6D8860-8764-4EEF-9FDD-89FF932791A7"
            },
            {
              "criteria": "cpe:2.3:a:discourse:discourse:3.4.0:beta2:*:*:beta:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6A7FC47A-8C19-4E39-B0CF-ADA835A02A9B"
            },
            {
              "criteria": "cpe:2.3:a:discourse:discourse:3.4.0:beta3:*:*:beta:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8802773F-8216-4F0F-9F58-89056BFBE8B8"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}