CVE-2023-43657

CVSS V2 None CVSS V3 None
Description
discourse-encrypt is a plugin that provides a secure communication channel through Discourse. Improper escaping of encrypted topic titles could lead to a cross site scripting (XSS) issue when a site has content security policy (CSP) headers disabled. Having CSP disabled is a non-default configuration, and having it disabled with discourse-encrypt installed will result in a warning in the Discourse admin dashboard. This has been fixed in commit `9c75810af9` which is included in the latest version of the discourse-encrypt plugin. Users are advised to upgrade. Users unable to upgrade should ensure that CSP headers are enabled and properly configured.
Overview
  • CVE ID
  • CVE-2023-43657
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2023-09-28T18:04:26.672Z
  • Last Modified Date
  • 2023-09-28T18:04:26.672Z
History
Created Old Value New Value Data Type Notes
2024-06-25 16:07:12 Added to TrackCVE