CVE-2022-23549

MEDIUM

Discourse < 2.8.14 - Improper Input Validation

Title source: rule
STIX 2.1

Description

Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 2.9.0.beta16 on the `beta` and `tests-passed` branches, users can create posts with raw body longer than the `max_length` site setting by including html comments that are not counted toward the character limit. This issue is patched in versions 2.8.14 and 2.9.0.beta16. There are no known workarounds.

Scores

CVSS v3 5.7
EPSS 0.0033
EPSS Percentile 55.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (3)
discourse/discourse 2.9.0 beta1 (13 CPE variants)
discourse/discourse 3.0.0 beta15
discourse/discourse < 2.8.14
Published Jan 05, 2023
Tracked Since Feb 18, 2026