CVE-2023-49099

LOW

Discourse - Info Disclosure

Title source: llm
STIX 2.1

Description

Discourse is a platform for community discussion. Under very specific circumstances, secure upload URLs associated with posts can be accessed by guest users even when login is required. This vulnerability has been patched in 3.2.0.beta4 and 3.1.4.

Scores

CVSS v3 3.1
EPSS 0.0029
EPSS Percentile 52.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (2)
discourse/discourse 3.2.0 beta1 (3 CPE variants)
discourse/discourse < 3.1.4
Published Jan 12, 2024
Tracked Since Feb 18, 2026