Discourse is an open source discussion platform. A CSP (Content Security Policy) nonce reuse vulnerability could allow XSS attacks to bypass CSP protection. There are no known XSS vectors at the moment, but should one be discovered, this vulnerability would allow the XSS attack to completely bypass CSP. The vulnerability is patched in the latest tests-passed, beta and stable branches.
References
Link | Resource |
---|---|
https://github.com/discourse/discourse/security/advisories/GHSA-9f52-624j-8ppq | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2023-07-13 21:15
Updated : 2023-07-25 18:35
NVD link : CVE-2023-36473
Mitre link : CVE-2023-36473
CVE.ORG link : CVE-2023-36473
JSON object : View
Products Affected
discourse
- discourse
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')