CVE-2022-31095 MEDIUM

CVE-2022-31095: Exposure of Sensitive Information in discourse-chat

Vendor Discourse
Product discourse-chat
Weakness CWE-200 · Info exposure
Published June 21, 2022
Last update April 23, 2025

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

discourse-chat is a chat plugin for the Discourse application. Versions prior to 0.4 are vulnerable to an exposure of sensitive information, where an attacker who knows the message ID for a channel they do not have access to can view that message using the chat message lookup endpoint, primarily affecting direct message channels. There are no known workarounds for this issue, and users are advised to update the plugin.

Key dates

02Disclosure timeline

June 21, 2022 CVE published
April 23, 2025 Record updated