Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-54142

Опубликовано: 14 янв. 2025
Источник: nvd
CVSS3: 9
EPSS Низкий

Описание

Discourse AI is a Discourse plugin which provides a number of AI features. When sharing Discourse AI Bot conversations into posts, if the conversation had HTML entities those could leak into the Discourse application when a user visited a post with a onebox to said conversation. This issue has been addressed in commit 92f122c. Users are advised to update. Users unable to update may remove all groups from ai bot public sharing allowed groups site setting.

EPSS

Процентиль: 36%
0.00151
Низкий

9 Critical

CVSS3

Дефекты

CWE-79

EPSS

Процентиль: 36%
0.00151
Низкий

9 Critical

CVSS3

Дефекты

CWE-79