CVE-2022-46162

CVSS V2 None CVSS V3 None
Description
discourse-bbcode is the official BBCode plugin for Discourse. Prior to commit 91478f5, CSS injection can occur when rendering content generated with the discourse-bccode plugin. This vulnerability only affects sites which have the discourse-bbcode plugin installed and enabled. This issue is patched in commit 91478f5. As a workaround, ensure that the Content Security Policy is enabled and monitor any posts that contain bbcode.
Overview
  • CVE ID
  • CVE-2022-46162
  • Assigner
  • security-advisories@github.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2022-11-30T23:15:10.673
  • Last Modified Date
  • 2022-12-02T16:36:09.930
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:discourse:discourse_bbcode:*:*:*:*:*:discourse:*:* 1 OR 2022-11-30
History
Created Old Value New Value Data Type Notes
2022-12-07 18:05:44 Added to TrackCVE