Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-43840

18
FAUCET Score

CVE-2021-43840 is a path traversal vulnerability affecting the message_bus Ruby gem, specifically versions prior to 3.3.7, when diagnostic features are enabled. This flaw allows an authenticated attacker to potentially disclose sensitive information from the host system. With a CVSS score of 6.5 (Medium), the vulnerability has a network attack vector and low attack complexity, leading to high confidentiality impact. There is currently no evidence of active exploitation, nor are public exploit codes or Metasploit modules available, and it has received minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.3.7CPE matchmatch criteria
cpe:2.3:a:discourse:message_bus:*:*:*:*:*:ruby:*:*

CVSS Data

CVSS version used by this source: 3.1

4.4MEDIUM

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
0.7
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.87%
Probability of exploitation in next 30 days
EPSS Percentile
77.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0187 is in the 90th percentile among its peer group of 21,957 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
rubygemspatch availablevia ghsa
Product: message_busFixed in: 3.3.7

Vendor Advisories (1)

rubygemsGHSA-xmgj-5fh3-xjmmmedium

Path traversal when MessageBus::Diagnostics is enabled

Dec 17, 2021

References

github.com / discourse/message_bus/commit/9b6deee01ed474c7e9b5ff65a06bb0447b4db2ba
PatchThird Party Advisory
github.com / discourse/message_bus/security/advisories/GHSA-xmgj-5fh3-xjmm
Third Party Advisory