« Back to list

CVE-2022-46159

Status: ModifiedMedium (4.3)—

Discourse is an open-source discussion platform. In version 2.8.13 and prior on the `stable` branch and version 2.9.0.beta14 and prior on the `beta` and `tests-passed` branches, any authenticated user can create an unlisted topic. These topics, which are not readily available to other users, can take up unnecessary site resources. A patch for this issue is available in the `main` branch of Discourse. There are no known workarounds available.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2022-46159",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-46159",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-23T13:53:15.607538Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "discourse",
          "product": "discourse",
          "versions": [
            {
              "status": "affected",
              "version": "<= 2.8.13"
            },
            {
              "status": "affected",
              "version": ">= 2.9.0.beta0, <= 2.9.0.beta14"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-12-02T15:15:10.090",
  "references": [
    {
      "url": "https://github.com/discourse/discourse/commit/0ce38bd7bce862db251b882613ab7053ca777382",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/discourse/discourse/security/advisories/GHSA-qf99-xpx6-hgxp",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/discourse/discourse/commit/0ce38bd7bce862db251b882613ab7053ca777382",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/discourse/discourse/security/advisories/GHSA-qf99-xpx6-hgxp",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-770"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Discourse is an open-source discussion platform. In version 2.8.13 and prior on the `stable` branch and version 2.9.0.beta14 and prior on the `beta` and `tests-passed` branches, any authenticated user can create an unlisted topic. These topics, which are not readily available to other users, can take up unnecessary site resources. A patch for this issue is available in the `main` branch of Discourse. There are no known workarounds available.\n"
    },
    {
      "lang": "es",
      "value": "Discourse es una plataforma de discusión de código abierto. En la versión 2.8.13 y anteriores en la rama `stable` y en la versión 2.9.0.beta14 y anteriores en las ramas `beta` y `tests-passed`, cualquier usuario autenticado puede crear un tema no listado. Estos temas, que no están disponibles para otros usuarios, pueden consumir recursos innecesarios del sitio. Hay un parche para este problema disponible en la rama \"principal\" de Discourse. No se conocen workarounds disponibles."
    }
  ],
  "lastModified": "2026-06-17T05:11:19.803",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F0A7BB8C-9904-42B5-8D91-0275CCA5D74F",
              "versionEndIncluding": "2.8.13"
            },
            {
              "criteria": "cpe:2.3:a:discourse:discourse:2.9.0:beta1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B3803EF9-A296-42B7-887F-93C5E68E94C4"
            },
            {
              "criteria": "cpe:2.3:a:discourse:discourse:2.9.0:beta10:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "35BAC488-3622-4B0B-B8EA-879E8C68E8CF"
            },
            {
              "criteria": "cpe:2.3:a:discourse:discourse:2.9.0:beta11:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "406A23B4-B971-4DC8-A132-EE9854FE8546"
            },
            {
              "criteria": "cpe:2.3:a:discourse:discourse:2.9.0:beta12:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1DD3C47F-E49F-4E19-9EA7-A322C4CFD541"
            },
            {
              "criteria": "cpe:2.3:a:discourse:discourse:2.9.0:beta13:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E924AC08-6978-4DFF-B616-9E3E9D6FBE1B"
            },
            {
              "criteria": "cpe:2.3:a:discourse:discourse:2.9.0:beta14:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B5A3C7FB-B3B6-45F0-AD7D-062A50490AD7"
            },
            {
              "criteria": "cpe:2.3:a:discourse:discourse:2.9.0:beta2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8BA3D313-3C11-43E2-A47D-CBB532D1B6F8"
            },
            {
              "criteria": "cpe:2.3:a:discourse:discourse:2.9.0:beta3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6F42673E-65F3-4807-9484-20CB747420FB"
            },
            {
              "criteria": "cpe:2.3:a:discourse:discourse:2.9.0:beta4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0B91D023-FCE5-4866-AD8B-BBB675763104"
            },
            {
              "criteria": "cpe:2.3:a:discourse:discourse:2.9.0:beta5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0086484D-0164-449C-8AAE-BE7479CB9706"
            },
            {
              "criteria": "cpe:2.3:a:discourse:discourse:2.9.0:beta6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F9D1B031-96C7-44C0-A0A0-F67ABE55C93C"
            },
            {
              "criteria": "cpe:2.3:a:discourse:discourse:2.9.0:beta7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "750D2AD9-35E7-4AC7-9C22-AA90DAA34F3F"
            },
            {
              "criteria": "cpe:2.3:a:discourse:discourse:2.9.0:beta8:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B68E308A-BDAB-4614-A563-4460F7996CBE"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}