« Back to list

CVE-2022-23548

Status: ModifiedMedium (6.5)—

Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 2.9.0.beta16 on the `beta` and `tests-passed` branches, parsing posts can be susceptible to regular expression denial of service (ReDoS) attacks. This issue is patched in versions 2.8.14 and 2.9.0.beta16. There are no known workarounds.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2022-23548",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-23548",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-03-10T21:00:33.992880Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "discourse",
          "product": "discourse",
          "versions": [
            {
              "status": "affected",
              "version": "< 2.8.14"
            },
            {
              "status": "affected",
              "version": ">= 2.9.0.beta0, <  2.9.0.beta16"
            }
          ]
        }
      ]
    }
  ],
  "published": "2023-01-05T19:15:09.423",
  "references": [
    {
      "url": "https://github.com/discourse/discourse/pull/19737",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/discourse/discourse/security/advisories/GHSA-7rw2-f4x7-7pxf",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/discourse/discourse/pull/19737",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/discourse/discourse/security/advisories/GHSA-7rw2-f4x7-7pxf",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-1333"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-1333"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 2.9.0.beta16 on the `beta` and `tests-passed` branches, parsing posts can be susceptible to regular expression denial of service (ReDoS) attacks. This issue is patched in versions 2.8.14 and 2.9.0.beta16. There are no known workarounds."
    },
    {
      "lang": "es",
      "value": "Discourse es una plataforma de discusión de fuentes de opciones. Antes de la versión 2.8.14 en la rama `stable` y la versión 2.9.0.beta16 en las ramas `beta` y `tests-passed`, el análisis de publicaciones puede ser susceptible a ataques de denegación de servicio (ReDoS) de expresión regular. Este problema se solucionó en las versiones 2.8.14 y 2.9.0.beta16. No se conocen workarounds."
    }
  ],
  "lastModified": "2026-06-17T04:30:20.130",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9C13BCBA-EF34-4F4B-9F4A-33392EB45196",
              "versionEndExcluding": "2.8.14"
            },
            {
              "criteria": "cpe:2.3:a:discourse:discourse:2.9.0:beta1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B3803EF9-A296-42B7-887F-93C5E68E94C4"
            },
            {
              "criteria": "cpe:2.3:a:discourse:discourse:2.9.0:beta10:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "35BAC488-3622-4B0B-B8EA-879E8C68E8CF"
            },
            {
              "criteria": "cpe:2.3:a:discourse:discourse:2.9.0:beta11:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "406A23B4-B971-4DC8-A132-EE9854FE8546"
            },
            {
              "criteria": "cpe:2.3:a:discourse:discourse:2.9.0:beta12:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1DD3C47F-E49F-4E19-9EA7-A322C4CFD541"
            },
            {
              "criteria": "cpe:2.3:a:discourse:discourse:2.9.0:beta13:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E924AC08-6978-4DFF-B616-9E3E9D6FBE1B"
            },
            {
              "criteria": "cpe:2.3:a:discourse:discourse:2.9.0:beta14:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B5A3C7FB-B3B6-45F0-AD7D-062A50490AD7"
            },
            {
              "criteria": "cpe:2.3:a:discourse:discourse:2.9.0:beta2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8BA3D313-3C11-43E2-A47D-CBB532D1B6F8"
            },
            {
              "criteria": "cpe:2.3:a:discourse:discourse:2.9.0:beta3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6F42673E-65F3-4807-9484-20CB747420FB"
            },
            {
              "criteria": "cpe:2.3:a:discourse:discourse:2.9.0:beta4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0B91D023-FCE5-4866-AD8B-BBB675763104"
            },
            {
              "criteria": "cpe:2.3:a:discourse:discourse:2.9.0:beta5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0086484D-0164-449C-8AAE-BE7479CB9706"
            },
            {
              "criteria": "cpe:2.3:a:discourse:discourse:2.9.0:beta6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F9D1B031-96C7-44C0-A0A0-F67ABE55C93C"
            },
            {
              "criteria": "cpe:2.3:a:discourse:discourse:2.9.0:beta7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "750D2AD9-35E7-4AC7-9C22-AA90DAA34F3F"
            },
            {
              "criteria": "cpe:2.3:a:discourse:discourse:2.9.0:beta8:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B68E308A-BDAB-4614-A563-4460F7996CBE"
            },
            {
              "criteria": "cpe:2.3:a:discourse:discourse:3.0.0:beta15:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F62275F8-11E9-4D94-8F2E-F83905F65031"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}