CVE-2023-32301

MEDIUM5.3EPSS 0.21%

Discourse's canonical url not being used for topic embeddings

發布日:2024/3/6修改日:2025/10/15
也稱為:GHSA-p2jx-m2j5-hqh4BIT-discourse-2023-32301

描述

Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passed` branches, multiple duplicate topics could be created if topic embedding is enabled. This issue is patched in version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passed` branches. As a workaround, disable topic embedding if it has been enabled.

受影響套件(1)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

參考連結(2)