PT-2021-23140 · Discourse · Discourse

Joernchen

·

Published

2021-10-20

·

Updated

2024-03-06

·

CVE-2021-41163

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Discourse versions 2.7.8 and earlier
Description Discourse is an open source platform for community discussion. In affected versions, maliciously crafted requests could lead to remote code execution. This resulted from a lack of validation in subscribe url values. It is estimated that around 14,300 sites are potentially vulnerable, with 8,639 potentially vulnerable systems located in the USA.
Recommendations To resolve the issue, update to version 2.7.9 or later. As a temporary workaround, consider blocking requests with a path starting with /webhooks/aws at an upstream proxy.

Fix

RCE

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2021-41163
CVE-2021-41163
GHSA-JCJX-PVPC-QGWQ

Affected Products

Discourse