Aller au contenu

Fiche vulnérabilité

CVE-2021-41163 : faille critique discourse discourse (CVSS 9.8)

Description

Discourse is an open source platform for community discussion. In affected versions maliciously crafted requests could lead to remote code execution. This resulted from a lack of validation in subscribe_url values. This issue is patched in the latest stable, beta and tests-passed versions of Discourse. To workaround the issue without updating, requests with a path starting /webhooks/aws path could be blocked at an upstream proxy.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
20 oct. 2021
Dernière mise à jour
17 juin 2026

Produits concernés

  • discourse discourse

Références

Rechercher une autre vulnérabilité dans la base CVE