Discourse is an open source platform for community discussion. In affected versions an attacker can make craft an XHR request to poison the anonymous cache (for example, the cache may have a response with missing preloaded data). This issue only affects anonymous visitors of the site. This problem has been patched in the latest version of Discourse. Users are advised to upgrade. Users unable to upgrade should disable anonymous cache by setting the `DISCOURSE_DISABLE_ANON_CACHE` environment variable to a non-empty value.
History

Tue, 04 Feb 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Feb 2025 21:15:00 +0000

Type Values Removed Values Added
Description Discourse is an open source platform for community discussion. In affected versions an attacker can make craft an XHR request to poison the anonymous cache (for example, the cache may have a response with missing preloaded data). This issue only affects anonymous visitors of the site. This problem has been patched in the latest version of Discourse. Users are advised to upgrade. Users unable to upgrade should disable anonymous cache by setting the `DISCOURSE_DISABLE_ANON_CACHE` environment variable to a non-empty value.
Title Anonymous cache poisoning via XHR requests in Discourse
Weaknesses CWE-346
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-02-04T21:01:59.746Z

Updated: 2025-02-04T21:23:21.326Z

Reserved: 2024-12-13T17:39:32.960Z

Link: CVE-2024-55948

cve-icon Vulnrichment

Updated: 2025-02-04T21:23:17.679Z

cve-icon NVD

Status : Received

Published: 2025-02-04T21:15:27.123

Modified: 2025-02-04T21:15:27.123

Link: CVE-2024-55948

cve-icon Redhat

No data.