peter bassill · operator
$ cve CVE-2024-47773 JSON

CVE-2024-47773 EXPLOIT

8.2
HIGH · CVSS 3.1 · EPSS 1.7% (pctl 76)

Patch early

A public exploit exists.

Description

Discourse is an open source platform for community discussion. An attacker can make several XHR requests until the cache is poisoned with a response without any preloaded data. This issue only affects anonymous visitors of the site. This problem has been patched in the latest version of Discourse. Users are advised to upgrade. Users unable to upgrade should disable anonymous cache by setting the `DISCOURSE_DISABLE_ANON_CACHE` environment variable to a non-empty value.

Scoring

CVSS8.2 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
EPSS1.66% — more likely to be exploited than 76% of all CVEs
WeaknessCWE-610
On CISA KEVno
Public exploityes
Published2024-10-08
Last modified2026-06-17

Affected (1)

VendorProduct
discoursediscourse

Public exploits

SourceTitleDate
exploit-dbDiscourse 3.2.x - Anonymous Cache Poisoning2025-07-08

References

→ the Explorer  ·  watch your stack  ·  NVD