Server Side Request Forgery (SSRF) vulnerability exists in Discourse 2.3.2 and 2.6 via the email function. When writing an email in an editor, you can upload pictures of remote websites.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2021-09-23T17:48:51

Updated: 2024-08-04T15:12:08.506Z

Reserved: 2020-08-13T00:00:00

Link: CVE-2020-24327

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-09-23T18:15:08.777

Modified: 2021-09-29T21:34:10.253

Link: CVE-2020-24327

cve-icon Redhat

No data.