Low severity2.6NVD Advisory· Published Jun 7, 2022· Updated Jun 17, 2026
CVE-2022-31025
CVE-2022-31025
Description
Discourse is an open source platform for community discussion. Prior to version 2.8.4 on the stable branch and 2.9.0beta5 on the beta and tests-passed branches, inviting users on sites that use single sign-on could bypass the must_approve_users check and invites by staff are always approved automatically. The issue is patched in Discourse version 2.8.4 on the stable branch and version 2.9.0.beta5 on the beta and tests-passed branches. As a workaround, disable invites or increase min_trust_level_to_allow_invite to reduce the attack surface to more trusted users.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*range: <2.8.4
- cpe:2.3:a:discourse:discourse:2.9.0:beta1:*:*:*:*:*:*
- cpe:2.3:a:discourse:discourse:2.9.0:beta2:*:*:*:*:*:*
- cpe:2.3:a:discourse:discourse:2.9.0:beta3:*:*:*:*:*:*
- cpe:2.3:a:discourse:discourse:2.9.0:beta4:*:*:*:*:*:*
- (no CPE)range: <2.8.4, <2.9.0.beta5
- (no CPE)range: < 2.8.4
Patches
Vulnerability mechanics
References
5- github.com/discourse/discourse/commit/0fa0094531efc82d9371f90a02aa804b176d59cfnvdPatchThird Party Advisory
- github.com/discourse/discourse/commit/7c4e2d33fa4b922354c177ffc880a2f2701a91f9nvdPatchThird Party Advisory
- github.com/discourse/discourse/pull/16974nvdPatchThird Party Advisory
- github.com/discourse/discourse/pull/16984nvdPatchThird Party Advisory
- github.com/discourse/discourse/security/advisories/GHSA-x7jh-mx5q-6f9qnvdThird Party Advisory
News mentions
0No linked articles in our index yet.