Admin-Initiated SSRF Attacks Vulnerability in Discourse-AI Plugin
CVE-2024-23654

4.1MEDIUM

Key Information:

Vendor
discourse
Vendor
CVE Published:
21 February 2024

Summary

discourse-ai is the AI plugin for the open-source discussion platform Discourse. Prior to commit 94ba0dadc2cf38e8f81c3936974c167219878edd, interactions with different AI services are vulnerable to admin-initiated SSRF attacks. Versions of the plugin that include commit 94ba0dadc2cf38e8f81c3936974c167219878edd contain a patch. As a workaround, one may disable the discourse-ai plugin.

Affected Version(s)

discourse-ai < 94ba0dadc2cf38e8f81c3936974c167219878edd

References

CVSS V3.1

Score:
4.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.