PT-2021-19913 · Discourse · Discourse

Davidtaylorhq

·

Published

2021-07-15

·

Updated

2024-03-06

·

CVE-2021-32764

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Discourse versions 2.7.5 and prior
Description Discourse is an open-source discussion platform. The parsing and rendering of YouTube Oneboxes can be susceptible to XSS attacks in versions where the default Content Security Policy has been modified or disabled.
Recommendations For versions 2.7.5 and prior, update to stable version 2.7.6, beta version 2.8.0.beta3, or tests-passed version 2.8.0.beta3 to resolve the issue. As a temporary workaround, ensure that the Content Security Policy is enabled and has not been modified in a way that would make it more vulnerable to XSS attacks.

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2021-32764
CVE-2021-32764
GHSA-9X4C-29XG-56HW

Affected Products

Discourse