Discourse Plugin Vulnerability Affects Microsoft Authentication
CVE-2023-46241
Key Information:
- Vendor
Discourse
- Status
- Vendor
- CVE Published:
- 21 February 2024
What is CVE-2023-46241?
The discourse-microsoft-auth
plugin, designed for Microsoft-based user authentication on Discourse platforms, contains a vulnerability that may expose user accounts to unauthorized control. This issue arises when sites are configured with account types beyond Accounts in this organizational directory only (O365 only - Single tenant)
. Attackers may exploit this configuration to manipulate user accounts, potentially compromising sensitive information. Affected sites are advised to apply the patch available in commit c40665f44509724b64938c85def9fb2e79f62ec8, which includes a new microsoft_auth:revoke
rake task. This task not only logs out affected users but also revokes their API keys and disconnects their accounts from Microsoft. Administrators can temporarily mitigate risk by disabling the plugin until the patch is fully implemented.
Affected Version(s)
discourse-microsoft-auth < c40665f44509724b64938c85def9fb2e79f62ec8