CVE-2024-53991

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Dec 19, 2024
CWE ID 200

Summary

CVE-2024-53991 is a vulnerability affecting Discourse, an open-source community discussion platform. This issue specifically targets Discourse instances configured with `FileStore::LocalStore`, allowing uploads and backups to be stored locally. Maliciously named requests to the nginx server can trick it into sending the Discourse backup file to an attacker. To mitigate this risk, Discourse users are advised to upgrade to the latest stable, beta, or tests-passed versions. Alternatively, users can download local backups onto an external storage device, disable backups, or change the `backup_location` setting to Amazon S3 for secure storage and downloading.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share