SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-46180

Discourse Mermaid (discourse-mermaid-theme-component) allows users of Discourse, open-source forum software, to create graphs using the Mermaid syntax.

MEDIUM 5.4EPSS 0.47%

Does this matter?

Lower severity and a low EPSS score (0.47%). Track it; it rarely justifies an emergency change on its own.

Description

Discourse Mermaid (discourse-mermaid-theme-component) allows users of Discourse, open-source forum software, to create graphs using the Mermaid syntax. Users of discourse-mermaid-theme-component version 1.0.0 who can create posts are able to inject arbitrary HTML on that post. The issue has been fixed on the `main` branch of the GitHub repository, with 1.1.0 named as a patched version. Admins can update the theme component through the admin UI. As a workaround, admins can temporarily disable discourse-mermaid-theme-component.

CVSS 3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS
0.47% probability · 39th percentile
CISA KEV
Not listed
Weakness
CWE-74, CWE-79
Affected
discourse/mermaid
Source
security-advisories@github.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.