Discourse is an open source community platform. In affected versions any user can create a topic and add arbitrary custom fields to a topic. The severity of this vulnerability depends on what plugins are installed and how the plugins uses topic custom fields. For a default Discourse installation with the default plugins, this vulnerability has no impact. The problem has been patched in the latest version of Discourse. Users are advised to update to version 3.1.1 if they are on the stable branch or 3.2.0.beta2 if they are on the beta branch. Users unable to upgrade should disable any plugins that access topic custom fields.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2023-10-16T20:26:25.200Z
Updated: 2024-09-13T19:00:16.296Z
Reserved: 2023-10-04T16:02:46.330Z
Link: CVE-2023-45147
Vulnrichment
Updated: 2024-08-02T20:14:19.800Z
NVD
Status : Modified
Published: 2023-10-16T21:15:11.433
Modified: 2024-11-21T08:26:26.637
Link: CVE-2023-45147
Redhat
No data.