Headline
CVE-2023-28111: SECURITY: Multiple commits for version bump beta3 by oblakeerickson · Pull Request #20710 · discourse/discourse
Discourse is an open-source discussion platform. Prior to version 3.1.0.beta3 of the beta
and tests-passed
branches, attackers are able to bypass Discourse’s server-side request forgery (SSRF) protection for private IPv4 addresses by using a IPv4-mapped IPv6 address. The issue is patched in the latest beta and tests-passed version of Discourse. version 3.1.0.beta3 of the beta
and tests-passed
branches. There are no known workarounds.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
Pick a username
Email Address
Password
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account