← Back

CVE-2024-23834

nvd nist
Published: Jan 30, 2024Modified: Nov 21, 2024

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

Discourse is an open-source discussion platform. Improperly sanitized user input could lead to an XSS vulnerability in some situations. This vulnerability only affects Discourse instances which have disabled the default Content Security Policy. The vulnerability is patched in 3.1.5 and 3.2.0.beta5. As a workaround, ensure Content Security Policy is enabled and does not include `unsafe-inline`.

Affected (6)

Products: Discourse: Discourse
1 product
Discourse
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Discourse
Before 3.2.0
Before 3.1.5
Version 3.2.0 beta1
Version 3.2.0 beta2
Version 3.2.0 beta3
Version 3.2.0 beta4

References (8)

Timeline

No history available yet.