Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Highjomax

#18378of 53,624
14.7Total CVSS
Vulnerabilities · 2
High
2
PT-2023-29429
7.5
2023-10-16
Discourse · Discourse · CVE-2023-45131
**Name of the Vulnerable Software and Affected Versions** Discourse versions prior to 3.1.1 stable and 3.2.0.beta2 **Description** Discourse is an open source platform for community discussion. The issue allows new chat messages to be read by making an unauthenticated POST request to `MessageBus`. There are no known workarounds for this issue. Users are advised to upgrade to a patched version. **Recommendations** For versions prior to 3.1.1 stable, upgrade to version 3.1.1 stable or later. For versions prior to 3.2.0.beta2, upgrade to version 3.2.0.beta2 or later. As a temporary workaround, consider restricting access to the `MessageBus` until a patch is applied.
PT-2022-23155
7.2
2022-09-29
Discourse · Discourse · CVE-2022-36068
**Name of the Vulnerable Software and Affected Versions** Discourse versions prior to 2.8.9 Discourse versions prior to 2.9.0.beta10 **Description** The issue allows a moderator to create new and edit existing themes using the API when they should not have this capability. **Recommendations** For versions prior to 2.8.9, update to version 2.8.9 or later. For versions prior to 2.9.0.beta10, update to version 2.9.0.beta10 or later.