CVE-2024-23654 is a high-severity Server-Side Request Forgery (SSRF) vulnerability affecting the discourse-ai plugin for the Discourse discussion platform. An authenticated administrator can exploit this flaw to initiate requests from the server to arbitrary internal or external resources, potentially leading to information disclosure, unauthorized access, or further compromise. The vulnerability has been patched in versions of the plugin including commit 94ba0dadc2cf38e8f81c3936974c167219878edd, and disabling the plugin serves as a workaround. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2024-02-21CPE matchmatch criteria | cpe:2.3:a:discourse:ai:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.