Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-36057: XSS issue for channel names and descriptions

Discourse-Chat is an asynchronous messaging plugin for the Discourse open-source discussion platform. Users of Discourse Chat can be affected by admin users inserting HTML into chat titles and descriptions, causing a Cross-Site Scripting (XSS) attack. Version 0.9 contains a patch for this issue.

CVE
#xss

Impact

Users of discourse chat can be affected by admin users inserting HTML into chat titles and descriptions, causing an XSS attack.

Patches

Updating to the latest version of chat will have the patch to fix this.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907