PT-2021-21748 · Discourse · Discourse
Bananabr
·
Published
2021-08-09
·
Updated
2024-03-06
·
CVE-2021-37633
CVSS v3.1
7.4
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Discourse versions prior to 2.7.8
Description
The issue affects Discourse, an open source discussion platform, where rendering of d-popover tooltips can be susceptible to XSS attacks in versions prior to 2.7.8. This vulnerability only affects sites that have modified or disabled Discourse's default Content Security Policy.
Recommendations
For versions prior to 2.7.8, update to the latest stable version 2.7.8 to resolve the issue.
As a temporary workaround, ensure that the Content Security Policy is enabled and has not been modified in a way that would make it more vulnerable to XSS attacks.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Discourse