CVE-2023-28111: Discourse vulnerable to SSRF protection bypass possible with IPv4-mapped IPv6 addresses
Discourse is an open-source discussion platform. Prior to version 3.1.0.beta3 of the beta and tests-passed branches, attackers are able to bypass Discourse's server-side request forgery (SSRF) protection for private IPv4 addresses by using a IPv4-mapped IPv6 address. The issue is patched in the latest beta and tests-passed version of Discourse. version 3.1.0.beta3 of the beta and tests-passed branches. There are no known workarounds.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-28111?
CVE-2023-28111 is a vulnerability in the Discourse open-source discussion platform that allows attackers to bypass server-side request forgery (SSRF) protection.
How does CVE-2023-28111 affect Discourse?
CVE-2023-28111 affects Discourse versions up to and including 3.1.0-beta2, allowing attackers to bypass SSRF protection for private IPv4 addresses.
What is the severity of CVE-2023-28111?
CVE-2023-28111 has a severity rating of 7.5 (high).
Is there a patch available for CVE-2023-28111?
Yes, the issue is patched in version 3.1.0.beta3 of the beta and tests-passed branches.
Where can I find more information about CVE-2023-28111?
You can find more information about CVE-2023-28111 in the following references: [link1], [link2], [link3].