discourse-bbcode is the official BBCode plugin for Discourse. Prior to commit 91478f5, CSS injection can occur when rendering content generated with the discourse-bccode plugin. This vulnerability only affects sites which have the discourse-bbcode plugin installed and enabled. This issue is patched in commit 91478f5. As a workaround, ensure that the Content Security Policy is enabled and monitor any posts that contain bbcode.
References
Link | Resource |
---|---|
https://github.com/discourse/discourse-bbcode/commit/91478f5cfecdcc43cf85b997168a8ecfd0f8df90 | Patch Third Party Advisory |
https://github.com/discourse/discourse-bbcode/security/advisories/GHSA-8c87-xpqv-c7mp | Exploit Vendor Advisory |
https://github.com/discourse/discourse-bbcode/commit/91478f5cfecdcc43cf85b997168a8ecfd0f8df90 | Patch Third Party Advisory |
https://github.com/discourse/discourse-bbcode/security/advisories/GHSA-8c87-xpqv-c7mp | Exploit Vendor Advisory |
Configurations
History
21 Nov 2024, 07:30
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/discourse/discourse-bbcode/commit/91478f5cfecdcc43cf85b997168a8ecfd0f8df90 - Patch, Third Party Advisory | |
References | () https://github.com/discourse/discourse-bbcode/security/advisories/GHSA-8c87-xpqv-c7mp - Exploit, Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
07 Jul 2023, 19:04
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-79 | |
References | (CONFIRM) https://github.com/discourse/discourse-bbcode/security/advisories/GHSA-8c87-xpqv-c7mp - Exploit, Vendor Advisory |
02 Dec 2022, 16:36
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
CPE | cpe:2.3:a:discourse:discourse_bbcode:*:*:*:*:*:discourse:*:* | |
References | (MISC) https://github.com/discourse/discourse-bbcode/commit/91478f5cfecdcc43cf85b997168a8ecfd0f8df90 - Patch, Third Party Advisory | |
References | (CONFIRM) https://github.com/discourse/discourse-bbcode/security/advisories/GHSA-8c87-xpqv-c7mp - Exploit, Third Party Advisory |
01 Dec 2022, 02:03
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-11-30 23:15
Updated : 2024-11-21 07:30
NVD link : CVE-2022-46162
Mitre link : CVE-2022-46162
CVE.ORG link : CVE-2022-46162
JSON object : View
Products Affected
discourse
- discourse_bbcode