Discourse is an open source platform for community discussion. New chat messages can be read by making an unauthenticated POST request to MessageBus. This issue is patched in the 3.1.1 stable and 3.2.0.beta2 versions of Discourse. Users are advised to upgrade. There are no known workarounds for this vulnerability.
References
Link | Resource |
---|---|
https://github.com/discourse/discourse/security/advisories/GHSA-84gf-hhrc-9pw6 | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: GitHub_M
Published: 2023-10-16T21:24:10.688Z
Updated: 2023-10-16T21:24:10.688Z
Reserved: 2023-10-04T16:02:46.328Z
Link: CVE-2023-45131
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-10-16T22:15:12.650
Modified: 2023-10-19T17:55:24.940
Link: CVE-2023-45131
JSON object: View
Redhat Information
No data.