Unrated severityNVD Advisory· Published Jul 3, 2024· Updated Aug 2, 2024
Discourse vulnerable to Server-Side Request Forgery via FastImage
CVE-2024-37157
Description
Discourse is an open-source discussion platform. Prior to version 3.2.3 on the stable branch and version 3.3.0.beta4 on the beta and tests-passed branches, a malicious actor could get the FastImage library to redirect requests to an internal Discourse IP. This issue is patched in version 3.2.3 on the stable branch and version 3.3.0.beta4 on the beta and tests-passed branches. No known workarounds are available.
Affected products
1- Range: stable < 3.2.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/discourse/discourse/commit/5b8cf11b69e05d5c058c1148ec69ec309491fa6emitrex_refsource_MISC
- github.com/discourse/discourse/commit/67e78086035cec494b15ce79342a0cb9052c2d95mitrex_refsource_MISC
- github.com/discourse/discourse/security/advisories/GHSA-46pq-7958-fc68mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.