Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-49099


Discourse is a platform for community discussion. Under very specific circumstances, secure upload URLs associated with posts can be accessed by guest users even when login is required. This vulnerability has been patched in 3.2.0.beta4 and 3.1.4.


Published

2024-01-12T21:15:09.747

Last Modified

2024-11-21T08:32:49.280

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 3.1 (LOW)

Weaknesses
  • Type: Secondary
    CWE-284

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application discourse discourse < 3.1.4 Yes
Application discourse discourse 3.2.0 Yes
Application discourse discourse 3.2.0 Yes
Application discourse discourse 3.2.0 Yes

References