CVE-2021-41271: Cache poisoning via maliciously-formed request in discourse
Discourse is a platform for community discussion. In affected versions a maliciously crafted request could cause an error response to be cached by intermediate proxies. This could cause a loss of confidentiality for some content. This issue is patched in the latest stable, beta and tests-passed versions of Discourse.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-41271?
CVE-2021-41271 has a medium severity rating due to its potential to cause confidentiality loss.
How do I fix CVE-2021-41271?
To fix CVE-2021-41271, upgrade to the latest stable version of Discourse beyond version 2.7.9.
What versions of Discourse are affected by CVE-2021-41271?
CVE-2021-41271 affects Discourse versions up to and including 2.7.9 and all beta versions of 2.8.0.
What type of vulnerability is CVE-2021-41271?
CVE-2021-41271 is a vulnerability that allows a maliciously crafted request to be cached, which may lead to exposure of sensitive content.
Is there a patch available for CVE-2021-41271?
Yes, a patch for CVE-2021-41271 is included in the latest stable releases of Discourse, beyond the affected versions.