CVE-2024-47773
Discourse is an open source platform for community discussion. An attacker can make several XHR requests until the cache is poisoned with a response without any preloaded data. This issue only affects anonymous visitors of the site. This problem has been patched in the latest version of Discourse. Users are advised to upgrade. Users unable to upgrade should disable anonymous cache by setting the `DISCOURSE_DISABLE_ANON_CACHE` environment variable to a non-empty value.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.2
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
- EPSS probability
- 1.66%
- CWE
- CWE-610
- Published
- 2024-10-08
- Last modified
- 2026-03-13
Affected products
- discourse discourse
- discourse discourse
Weakness type
Related vulnerabilities
- CVE-2026-19032 — jackson-databind resolves attacker-controlled URI schemes when deserializing java.nio.file.Path
- CVE-2026-21810 — HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and downloading code without integrity checking
- CVE-2026-79256 — Externally controlled reference in WebView in Google Chrome on on Android prior to 152.0.7977.65...
- CVE-2026-78966 — Externally controlled reference in QUIC in Google Chrome prior to 152.0.7977.65 allowed a remote...
- CVE-2026-62960 — Git for Windows: Server-advertised bundle-uri can trigger outbound SMB callbacks via UNC and file:// paths on Windows
- CVE-2026-76572 — pkp pkp-lib XSLTransformer.php _transformPHP xml external entity reference
- CVE-2026-68562 — Ansible-collection-redhat-leapp: ansible-collection-redhat-leapp: information disclosure via leapp report tampering
- CVE-2026-55389 — datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`