CVE-2022-36066
In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.beta10 on the `beta` and `tests-passed` branches, admins can upload a maliciously crafted Zip or Gzip Tar archive to write files at arbitrary locations and trigger remote code execution.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.66%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.beta10 on the `beta` and `tests-passed` branches, admins can upload a maliciously crafted Zip or Gzip Tar archive to write files at arbitrary locations and trigger remote code execution. The problem is patched in version 2.8.9 on the `stable` branch and version 2.9.0.beta10 on the `beta` and `tests-passed` branches. There are no known workarounds.
- CVSS 3.1
- 7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.66% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-434
- Affected
- discourse/discourse
- Source
- security-advisories@github.com
References
- https://github.com/discourse/discourse/commit/b27d5626d208a22c516a0adfda7554b67b493835Patch, Third Party Advisory
- https://github.com/discourse/discourse/pull/18421Patch, Third Party Advisory
- https://github.com/discourse/discourse/security/advisories/GHSA-grvh-qcpg-hfmvThird Party Advisory
- https://github.com/discourse/discourse/commit/b27d5626d208a22c516a0adfda7554b67b493835Patch, Third Party Advisory
- https://github.com/discourse/discourse/pull/18421Patch, Third Party Advisory
- https://github.com/discourse/discourse/security/advisories/GHSA-grvh-qcpg-hfmvThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.