XSRF Vulnerability in Discourse Community Forum Software
CVE-2024-55948
Summary
An identified vulnerability in the Discourse platform allows for the potential exploitation via crafted XHR requests that can poison the anonymous cache. This issue specifically affects anonymous visitors, leading to responses that might lack essential preloaded data. Despite its impact, the situation can be mitigated by upgrading to the latest version of Discourse. For users unable to implement the update, a temporary fix is to disable the anonymous cache by setting the DISCOURSE_DISABLE_ANON_CACHE
environment variable to a non-empty value. For more details, refer to the official advisory.
Affected Version(s)
discourse stable: < 3.3.2 < stable: 3.3.2
discourse tests-passed: < 3.4.0.beta3 < tests-passed: 3.4.0.beta3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved