Discourse is an open source platform for community discussion. An attacker can make several XHR requests until the cache is poisoned with a response without any preloaded data. This issue only affects anonymous visitors of the site. This problem has been patched in the latest version of Discourse. Users are advised to upgrade. Users unable to upgrade should disable anonymous cache by setting the `DISCOURSE_DISABLE_ANON_CACHE` environment variable to a non-empty value.
History

Tue, 08 Oct 2024 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Discourse
Discourse discourse
CPEs cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*
Vendors & Products Discourse
Discourse discourse
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Oct 2024 18:15:00 +0000

Type Values Removed Values Added
Description Discourse is an open source platform for community discussion. An attacker can make several XHR requests until the cache is poisoned with a response without any preloaded data. This issue only affects anonymous visitors of the site. This problem has been patched in the latest version of Discourse. Users are advised to upgrade. Users unable to upgrade should disable anonymous cache by setting the `DISCOURSE_DISABLE_ANON_CACHE` environment variable to a non-empty value.
Title Anonymous cache poisoning via XHR requests in Discourse
Weaknesses CWE-610
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-10-08T18:01:14.063Z

Updated: 2024-10-08T18:16:18.149Z

Reserved: 2024-09-30T21:28:53.233Z

Link: CVE-2024-47773

cve-icon Vulnrichment

Updated: 2024-10-08T18:16:13.827Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-10-08T18:15:30.720

Modified: 2024-10-10T12:56:30.817

Link: CVE-2024-47773

cve-icon Redhat

No data.