PT-2025-3011 · Discourse · Discourse
Jomaxro
·
Published
2025-02-04
·
Updated
2025-08-26
·
CVE-2024-53994
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Discourse versions prior to the latest version
Description
The issue affects users who disable chat in preferences but could still be reachable in some cases. The estimated number of potentially affected devices worldwide is not available. There is no information about real-world incidents where this issue was exploited.
Recommendations
For versions prior to the latest version, upgrade to the latest version of Discourse.
As a temporary workaround for users unable to upgrade, disable the chat plugin within site settings.
Exploit
Fix
Improper Preservation of Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Discourse