CVE-2022-31184

MEDIUM

Discourse - Info Disclosure

Title source: llm
STIX 2.1

Description

Discourse is the an open source discussion platform. In affected versions an email activation route can be abused to send mass spam emails. A fix has been included in the latest stable, beta and tests-passed versions of Discourse which rate limits emails. Users are advised to upgrade. Users unable to upgrade should manually rate limit email.

Scores

CVSS v3 6.5
EPSS 0.0035
EPSS Percentile 57.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-770
Status published
Products (2)
discourse/discourse 2.9.0 beta1 (7 CPE variants)
discourse/discourse < 2.8.6
Published Aug 01, 2022
Tracked Since Feb 18, 2026