Discourse is an open source platform for community discussion. New chat messages can be read by making an unauthenticated POST request to MessageBus. This issue is patched in the 3.1.1 stable and 3.2.0.beta2 versions of Discourse. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2023-10-16T21:24:10.688Z
Updated: 2024-09-16T15:41:43.734Z
Reserved: 2023-10-04T16:02:46.328Z
Link: CVE-2023-45131
Vulnrichment
Updated: 2024-08-02T20:14:19.752Z
NVD
Status : Modified
Published: 2023-10-16T22:15:12.650
Modified: 2024-11-21T08:26:24.310
Link: CVE-2023-45131
Redhat
No data.