CVE-2024-53991
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2024-53991 is a vulnerability affecting Discourse, an open-source community discussion platform. This issue specifically targets Discourse instances configured with `FileStore::LocalStore`, allowing uploads and backups to be stored locally. Maliciously named requests to the nginx server can trick it into sending the Discourse backup file to an attacker. To mitigate this risk, Discourse users are advised to upgrade to the latest stable, beta, or tests-passed versions. Alternatively, users can download local backups onto an external storage device, disable backups, or change the `backup_location` setting to Amazon S3 for secure storage and downloading.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.