Discourse is an open source discussion platform. A CSP (Content Security Policy) nonce reuse vulnerability could allow XSS attacks to bypass CSP protection. There are no known XSS vectors at the moment, but should one be discovered, this vulnerability would allow the XSS attack to completely bypass CSP. The vulnerability is patched in the latest tests-passed, beta and stable branches.
Attack Vector Network
Attack Complexity Low
Privileges Required None
Scope Changed
Confidentiality Impact Low
Integrity Impact Low
Availability Impact None
User Interaction Required
No CVSS v3.0
No CVSS v2
Vendors | Products |
---|---|
Discourse |
|
Configuration 1 [-]
|
References
Link | Resource |
---|---|
https://github.com/discourse/discourse/security/advisories/GHSA-9f52-624j-8ppq | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: GitHub_M
Published: 2023-07-13T20:57:50.880Z
Updated: 2023-07-13T20:57:50.880Z
Reserved: 2023-06-21T18:50:41.703Z
Link: CVE-2023-36473
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-07-13T21:15:08.957
Modified: 2023-07-25T18:35:53.763
Link: CVE-2023-36473
JSON object: View
Redhat Information
No data.
CWE