XSRF Vulnerability in Discourse Community Forum Software
CVE-2024-55948
8.2HIGH
Key Information:
What is CVE-2024-55948?
An identified vulnerability in the Discourse platform allows for the potential exploitation via crafted XHR requests that can poison the anonymous cache. This issue specifically affects anonymous visitors, leading to responses that might lack essential preloaded data. Despite its impact, the situation can be mitigated by upgrading to the latest version of Discourse. For users unable to implement the update, a temporary fix is to disable the anonymous cache by setting the DISCOURSE_DISABLE_ANON_CACHE
environment variable to a non-empty value. For more details, refer to the official advisory.
Affected Version(s)
discourse stable: < 3.3.2 < stable: 3.3.2
discourse tests-passed: < 3.4.0.beta3 < tests-passed: 3.4.0.beta3