CVE-2024-23654: discourse-ai admin-initiated SSRF when interacting with AI services
discourse-ai is the AI plugin for the open-source discussion platform Discourse. Prior to commit 94ba0dadc2cf38e8f81c3936974c167219878edd, interactions with different AI services are vulnerable to admin-initiated SSRF attacks. Versions of the plugin that include commit 94ba0dadc2cf38e8f81c3936974c167219878edd contain a patch. As a workaround, one may disable the discourse-ai plugin.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
discourse-aito a version that resolves this vulnerability.Patch 94ba0dadc2cf38e8f81c3936974c167219878edd - Configuration
Disable the discourse-ai plugin as a workaround.
Discourse discourse-ai plugin enabled = false
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23654?
CVE-2024-23654 is classified as a medium severity vulnerability due to its potential for admin-initiated SSRF attacks.
How do I fix CVE-2024-23654?
To fix CVE-2024-23654, update the discourse-ai plugin to a version that includes commit 94ba0dadc2cf38e8f81c3936974c167219878edd or later.
Who is affected by CVE-2024-23654?
Users of the discourse-ai plugin for Discourse prior to commit 94ba0dadc2cf38e8f81c3936974c167219878edd are affected by CVE-2024-23654.
What type of attacks does CVE-2024-23654 allow?
CVE-2024-23654 allows for server-side request forgery (SSRF) attacks that can be initiated by admins against different AI services.
Are there any known exploits for CVE-2024-23654?
As of now, there are no publicly known exploits specifically targeting CVE-2024-23654.