CVE-2024-37165 Information

Description

Discourse is an open source discussion platform. Prior to 3.2.3 and 3.3.0.beta3 improperly sanitized Onebox data could lead to an XSS vulnerability in some situations. This vulnerability only affects Discourse instances which have disabled the default Content Security Policy. This vulnerability is fixed in 3.2.3 and 3.3.0.beta3.

Reference

https://github.com/discourse/discourse/security/advisories/GHSA-cx83-5p6x-9qh9 https://github.com/discourse/discourse/commit/26aef0c288839378b9de5819e96eac8cf4ea60fd https://github.com/discourse/discourse/commit/311b737c910cf0a69f61e1b8bc0b78374b6619d2

Share on: