CVE-2021-41163
10.0
CRITICAL · CVSS 3.1 · EPSS 19.8% (pctl 97)
Patch early
EPSS 19.8% — above the 10% action threshold.
Description
Discourse is an open source platform for community discussion. In affected versions maliciously crafted requests could lead to remote code execution. This resulted from a lack of validation in subscribe_url values. This issue is patched in the latest stable, beta and tests-passed versions of Discourse. To workaround the issue without updating, requests with a path starting /webhooks/aws path could be blocked at an upstream proxy.
Scoring
| CVSS | 10.0 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 19.81% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-74 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2021-10-20 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| discourse | discourse |
References
- https://github.com/discourse/discourse/commit/fa3c46cf079d28b086fe1025349bb00223a5d5e9
- https://github.com/discourse/discourse/security/advisories/GHSA-jcjx-pvpc-qgwq
- https://github.com/discourse/discourse/commit/fa3c46cf079d28b086fe1025349bb00223a5d5e9
- https://github.com/discourse/discourse/security/advisories/GHSA-jcjx-pvpc-qgwq
→ the Explorer · watch your stack · NVD