CVE-2022-39232
Discourse is an open source discussion platform. Starting with version 2.9.0.beta5 and prior to version 2.9.0.beta10, an incomplete quote can generate a JavaScript error which will crash the current page in the browser in some cases. Version 2.9.0.beta10 added a fix and tests to ensure incomplete quotes won't break the app. As a workaround, the quote can be fixed via the rails console.
- Affected products
- Discourse
- Discourse
- = 2.9.0
- Fix
- Available
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 1.0% (60th percentile)
- Weakness
- CWE-20
- NVD status
- Modified
- Published
- 2022-09-29
CVE-2022-39232 at NVD
No indexed exploits for CVE-2022-39232 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2022-39232 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.