XSRF Vulnerability in Discourse Community Forum Software
CVE-2024-55948

8.2HIGH

Key Information:

Vendor
Discourse
Status
Vendor
CVE Published:
4 February 2025

Summary

An identified vulnerability in the Discourse platform allows for the potential exploitation via crafted XHR requests that can poison the anonymous cache. This issue specifically affects anonymous visitors, leading to responses that might lack essential preloaded data. Despite its impact, the situation can be mitigated by upgrading to the latest version of Discourse. For users unable to implement the update, a temporary fix is to disable the anonymous cache by setting the DISCOURSE_DISABLE_ANON_CACHE environment variable to a non-empty value. For more details, refer to the official advisory.

Affected Version(s)

discourse stable: < 3.3.2 < stable: 3.3.2

discourse tests-passed: < 3.4.0.beta3 < tests-passed: 3.4.0.beta3

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.