Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-42683 | Discourse is an open source platform for community discussion. An attacker can make several XHR requests until the cache is poisoned with a response without any preloaded data. This issue only affects anonymous visitors of the site. This problem has been patched in the latest version of Discourse. Users are advised to upgrade. Users unable to upgrade should disable anonymous cache by setting the `DISCOURSE_DISABLE_ANON_CACHE` environment variable to a non-empty value. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 26 Aug 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:discourse:discourse:*:*:*:*:stable:*:*:* |
Tue, 08 Oct 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Discourse
Discourse discourse |
|
| CPEs | cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Discourse
Discourse discourse |
|
| Metrics |
ssvc
|
Tue, 08 Oct 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Discourse is an open source platform for community discussion. An attacker can make several XHR requests until the cache is poisoned with a response without any preloaded data. This issue only affects anonymous visitors of the site. This problem has been patched in the latest version of Discourse. Users are advised to upgrade. Users unable to upgrade should disable anonymous cache by setting the `DISCOURSE_DISABLE_ANON_CACHE` environment variable to a non-empty value. | |
| Title | Anonymous cache poisoning via XHR requests in Discourse | |
| Weaknesses | CWE-610 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-10-08T18:16:18.149Z
Reserved: 2024-09-30T21:28:53.233Z
Link: CVE-2024-47773
Updated: 2024-10-08T18:16:13.827Z
Status : Analyzed
Published: 2024-10-08T18:15:30.720
Modified: 2025-08-26T16:58:28.737
Link: CVE-2024-47773
No data.
OpenCVE Enrichment
No data.
EUVD