Skip to content

Improper validation of email during Patreon authentication

Critical
jomaxro published GHSA-fvj9-f67v-qpr4 Oct 26, 2022

Package

discourse-patreon (Discourse)

Affected versions

< 0c88b9bf

Patched versions

>= 846d0121

Description

Impact

On sites with Patreon login enabled, this vulnerability could be used to take control of a victim's forum account.

Patches

This vulnerability is patched in the latest version of the discourse-patreon plugin. Out of an abundance of caution, any Discourse accounts which have logged in with an unverified-email Patreon account will be logged out and asked to verify their email address on their next login.

Workarounds

Disable the patreon integration and log out all users with associated Patreon accounts.

Severity

Critical
9.1
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CVE ID

CVE-2022-39355

Weaknesses

No CWEs