CVE-2022-39241

MEDIUM4.9EPSS 0.31%

Possible Server-Side Request Forgery (SSRF) in webhooks

Published: 3/6/2024Modified: 10/14/2025
Also known as:GHSA-rcc5-28r3-23rrBIT-discourse-2022-39241

Description

Discourse is a platform for community discussion. A malicious admin could use this vulnerability to perform port enumeration on the local host or other hosts on the internal network, as well as against hosts on the Internet. Latest `stable`, `beta`, and `test-passed` versions are now patched. As a workaround, self-hosters can use `DISCOURSE_BLOCKED_IP_BLOCKS` env var (which overrides `blocked_ip_blocks` setting) to stop webhooks from accessing private IPs.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM4.9CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

References (2)