CVE-2024-54142: Cross-site Scripting via Discourse-ai SharedAiConversation onebox in Discourse
Discourse AI is a Discourse plugin which provides a number of AI features. When sharing Discourse AI Bot conversations into posts, if the conversation had HTML entities those could leak into the Discourse application when a user visited a post with a onebox to said conversation. This issue has been addressed in commit 92f122c. Users are advised to update. Users unable to update may remove all groups from ai bot public sharing allowed groups site setting.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-54142?
The severity of CVE-2024-54142 is classified as medium, posing a risk of HTML entity leakage into the Discourse application.
How do I fix CVE-2024-54142?
To fix CVE-2024-54142, update to the latest version of the Discourse AI plugin that addresses this vulnerability.
Which versions of Discourse are affected by CVE-2024-54142?
CVE-2024-54142 affects all versions of Discourse that have the Discourse AI plugin installed.
What kind of data can be leaked due to CVE-2024-54142?
CVE-2024-54142 can lead to HTML entities from conversations leaking into posts when shared, affecting how content is rendered.
Can CVE-2024-54142 be exploited remotely?
Yes, CVE-2024-54142 can potentially be exploited remotely by users who have access to view posts with embedded oneboxes.