CVE-2023-49099
Description
Discourse is a platform for community discussion. Under very specific circumstances, secure upload URLs associated with posts can be accessed by guest users even when login is required. This vulnerability has been patched in 3.2.0.beta4 and 3.1.4.
- CVSS Version 3.1
nvd
CVE ID: CVE-2023-49099
Base Score: 4.3
Base Severity: MEDIUM
Vector String:CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Impact Score: 1.4
Exploitability Score: 2.8
github
CVE ID: CVE-2023-49099
Base Score: 3.1
Base Severity: LOW
Vector String:CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
Impact Score: 1.4
Exploitability Score: 1.6