Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-47121: SSRF vulnerability in Embedding

Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the stable branch and version 3.2.0.beta3 of the beta and tests-passed branches, the embedding feature is susceptible to server side request forgery. The issue is patched in version 3.1.3 of the stable branch and version 3.2.0.beta3 of the beta and tests-passed branches. As a workaround, disable the Embedding feature.

CVE
#vulnerability#ssrf

Low

jomaxro published GHSA-hp24-94qf-8cgc

Nov 9, 2023

Package

No package listed

Affected versions

stable < 3.1.3; beta/tests-passed < 3.2.0.beta3

Patched versions

stable >= 3.1.3; beta/tests-passed >= 3.2.0.beta3

Description

Impact

Embedding feature is susceptible to SSRF.

Patches

The issue is patched in the latest stable, beta and tests-passed version of Discourse.

Workarounds

Disable Embedding feature

Severity

CVSS base metrics

User interaction

Required

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907