THREATINT

We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Fathom (Privacy friendly web analytics)
Zendesk (Helpdesk and Chat)

Ok

Home | EN
Support
CVE
PUBLISHED

CVE-2024-35234

Discourse vulnerable to stored-dom XSS via Facebook Oneboxes

AssignerGitHub_M
Reserved2024-05-14
Published2024-07-03
Updated2024-07-08

Description

Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta3 on the `tests-passed` branch, an attacker can execute arbitrary JavaScript on users’ browsers by posting a specific URL containing maliciously crafted meta tags. This issue only affects sites with Content Security Polic (CSP) disabled. The problem has been patched in version 3.2.3 on the `stable` branch and version 3.3.0.beta3 on the `tests-passed` branch. As a workaround, ensure CSP is enabled on the forum.



MEDIUM: 4.2CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L

Problem types

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Product status

stable < 3.2.3
affected

tests-passed < 3.3.0.beta3
affected

References

https://github.com/discourse/discourse/security/advisories/GHSA-5chg-hm8c-wc58

https://github.com/discourse/discourse/commit/26aef0c288839378b9de5819e96eac8cf4ea60fd

https://github.com/discourse/discourse/commit/311b737c910cf0a69f61e1b8bc0b78374b6619d2

cve.org CVE-2024-35234

nvd.nist.gov CVE-2024-35234

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-35234
© Copyright 2024 THREATINT. Made in Cyprus with +