First published: Thu Sep 23 2021(Updated: )
Server Side Request Forgery (SSRF) vulnerability exists in Discourse 2.3.2 and 2.6 via the email function. When writing an email in an editor, you can upload pictures of remote websites.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Discourse Discourse | =2.3.2 | |
Discourse Discourse | =2.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.