PT-2023-25979 · Discourse · Discourse

Rothsn

+1

·

Publicado

2023-07-28

·

Atualizado

2024-03-06

·

CVE-2023-37467

CVSS v3.1

6.8

Média

VetorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Discourse versions prior to 3.1.0.beta7
Description A Content Security Policy (CSP) nonce reuse issue was discovered that could allow cross-site scripting (XSS) attacks to bypass CSP protection for anonymous users. Although there are no known XSS vectors at the moment, this issue would enable an XSS attack to bypass CSP and execute successfully if one were discovered. This issue does not affect logged-in users.
Recommendations For versions prior to 3.1.0.beta7, update to version 3.1.0.beta7 or later to resolve the issue. As a temporary workaround, consider disabling Google Tag Manager by unsetting the gtm container id setting to prevent the vulnerability.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BIT-DISCOURSE-2023-37467
CVE-2023-37467
GHSA-GR5H-HM62-JR3J

Produtos afetados

Discourse