CVE-2023-45131 is a critical vulnerability affecting Discourse, an open-source community discussion platform, allowing unauthenticated access to new chat messages via a POST request to MessageBus. With a CVSS score of 7.5 (High), this vulnerability poses a significant risk due to its low attack complexity and complete confidentiality impact without requiring any authentication. While not currently listed on the KEV catalog, an exploit (EDB-52375) is publicly available, though there is minimal community discussion or media coverage surrounding it. Users are strongly advised to upgrade to Discourse versions 3.1.1 stable or 3.2.0.beta2 immediately, as no workarounds exist.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.1.1CPE matchmatch criteria | cpe:2.3:a:discourse:discourse:*:*:*:*:stable:*:*:* | ||
3.2.0CPE matchmatch criteria | cpe:2.3:a:discourse:discourse:3.2.0:beta1:*:*:beta:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.