Unrated severityNVD Advisory· Published Jun 3, 2022· Updated Apr 23, 2025
Invite bypasses user approval in Discourse
CVE-2022-31025
Description
Discourse is an open source platform for community discussion. Prior to version 2.8.4 on the stable branch and 2.9.0beta5 on the beta and tests-passed branches, inviting users on sites that use single sign-on could bypass the must_approve_users check and invites by staff are always approved automatically. The issue is patched in Discourse version 2.8.4 on the stable branch and version 2.9.0.beta5 on the beta and tests-passed branches. As a workaround, disable invites or increase min_trust_level_to_allow_invite to reduce the attack surface to more trusted users.
Affected products
1- Range: < 2.8.4
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- github.com/discourse/discourse/commit/0fa0094531efc82d9371f90a02aa804b176d59cfmitrex_refsource_MISC
- github.com/discourse/discourse/commit/7c4e2d33fa4b922354c177ffc880a2f2701a91f9mitrex_refsource_MISC
- github.com/discourse/discourse/pull/16974mitrex_refsource_MISC
- github.com/discourse/discourse/pull/16984mitrex_refsource_MISC
- github.com/discourse/discourse/security/advisories/GHSA-x7jh-mx5q-6f9qmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.