Unauthenticated access to new private chat messages in Discourse
41Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 7.5epss 1.8%
from disclosure to weapon629 days
Published on NVDOct 16
1st PoC+629d
exploitation probability
1.8%top 23% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Discourse is an open source platform for community discussion. New chat messages can be read by making an unauthenticated POST request to MessageBus. This issue is patched in the 3.1.1 stable and 3.2.0.beta2 versions of Discourse. Users are advised to upgrade. There are no known workarounds for this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
discourse · discoursepublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/52375unverifiedgithubgithub.com/ibrahmsql/CVE-2023-45131★ 3⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.