Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-37157

Опубликовано: 03 июл. 2024
Источник: nvd
CVSS3: 6.4
CVSS3: 5.3
EPSS Низкий

Описание

Discourse is an open-source discussion platform. Prior to version 3.2.3 on the stable branch and version 3.3.0.beta4 on the beta and tests-passed branches, a malicious actor could get the FastImage library to redirect requests to an internal Discourse IP. This issue is patched in version 3.2.3 on the stable branch and version 3.3.0.beta4 on the beta and tests-passed branches. No known workarounds are available.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:discourse:discourse:*:*:*:*:stable:*:*:*
Версия до 3.2.3 (исключая)
cpe:2.3:a:discourse:discourse:*:*:*:*:beta:*:*:*
Версия до 3.3.0 (исключая)
cpe:2.3:a:discourse:discourse:3.3.0:beta1:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:3.3.0:beta2:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:3.3.0:beta3:*:*:beta:*:*:*

EPSS

Процентиль: 27%
0.00097
Низкий

6.4 Medium

CVSS3

5.3 Medium

CVSS3

Дефекты

CWE-918
CWE-918

EPSS

Процентиль: 27%
0.00097
Низкий

6.4 Medium

CVSS3

5.3 Medium

CVSS3

Дефекты

CWE-918
CWE-918