Description
Discourse is a platform for community discussion. Under very specific circumstances, secure upload URLs associated with posts can be accessed by guest users even when login is required. This vulnerability has been patched in 3.2.0.beta4 and 3.1.4.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-53108 | Discourse is a platform for community discussion. Under very specific circumstances, secure upload URLs associated with posts can be accessed by guest users even when login is required. This vulnerability has been patched in 3.2.0.beta4 and 3.1.4. |
References
History
Tue, 17 Jun 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-06-17T21:09:17.903Z
Reserved: 2023-11-21T18:57:30.430Z
Link: CVE-2023-49099
Updated: 2025-06-17T21:07:20.946Z
Status : Modified
Published: 2024-01-12T21:15:09.747
Modified: 2024-11-21T08:32:49.280
Link: CVE-2023-49099
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD