CVE-2022-31095

MEDIUM

Discourse-chat <0.4 - Info Disclosure

Title source: llm
STIX 2.1

Description

discourse-chat is a chat plugin for the Discourse application. Versions prior to 0.4 are vulnerable to an exposure of sensitive information, where an attacker who knows the message ID for a channel they do not have access to can view that message using the chat message lookup endpoint, primarily affecting direct message channels. There are no known workarounds for this issue, and users are advised to update the plugin.

References (1)

Core 1
Core References

Scores

CVSS v3 4.3
EPSS 0.0021
EPSS Percentile 42.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862 CWE-200
Status published
Products (1)
discourse/discourse-chat < 0.4
Published Jun 21, 2022
Tracked Since Feb 18, 2026