Discourse is the an open source discussion platform. In some rare cases users redeeming an invitation can be added as a participant to several private message topics that they should not be added to. They are not notified of this, it happens transparently in the background. This issue has been resolved in commit `a414520742` and will be included in future releases. Users are advised to upgrade. Users are also advised to set `SiteSetting.max_invites_per_day` to 0 until the patch is installed.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2022-11-14T00:00:00
Updated: 2024-08-03T12:07:42.500Z
Reserved: 2022-09-02T00:00:00
Link: CVE-2022-39385
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-11-14T21:15:15.007
Modified: 2024-11-21T07:18:11.163
Link: CVE-2022-39385
Redhat
No data.