CRITICAL🇵🇱 Wersja polska

CVE-2021-41163

CVSS 10.0v3.1pub. 2021-10-20upd. 2024-11-21

Discourse is an open source platform for community discussion. In affected versions maliciously crafted requests could lead to remote code execution. This resulted from a lack of validation in subscribe_url values. This issue is patched in the latest stable, beta and tests-passed versions of Discourse. To workaround the issue without updating, requests with a path starting /webhooks/aws path could be blocked at an upstream proxy.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Discourse

    APP
    Discourse
    2.8.0< 2.7.9
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2022-36066CRITICAL9.1PL ✓same product

Discourse: RCE przez przesłanie złośliwego archiwum Zip/Gzip Tar przez administratora

CVE-2026-55424HIGH7.4PL ✓same product

XSS w Discourse via niezwalidowany 'featured link' tematu

CVE-2026-55420HIGH7.5PL ✓same product

RCE via command injection przy przetwarzaniu plików PDF w Discourse

CVE-2026-53963HIGH7.3PL ✓same product

Stored XSS w Discourse przez złośliwą nazwę drugiego składnika uwierzytelniania

CVE-2026-27934HIGH8.7same product

Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 h...