Vulnerabilities > CVE-2023-49099 - Unspecified vulnerability in Discourse
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
LOW Integrity impact
NONE Availability impact
NONE Summary
Discourse is a platform for community discussion. Under very specific circumstances, secure upload URLs associated with posts can be accessed by guest users even when login is required. This vulnerability has been patched in 3.2.0.beta4 and 3.1.4.
Vulnerable Configurations
References
- https://github.com/discourse/discourse/commit/1b288236387fc0a823e4f15f1aea8dde81b49d53
- https://github.com/discourse/discourse/commit/1b288236387fc0a823e4f15f1aea8dde81b49d53
- https://github.com/discourse/discourse/security/advisories/GHSA-j67x-x6mq-pwv4
- https://github.com/discourse/discourse/security/advisories/GHSA-j67x-x6mq-pwv4