CVE-2024-23654
CVSS V2 None
CVSS V3 None
Description
discourse-ai is the AI plugin for the open-source discussion platform Discourse. Prior to commit 94ba0dadc2cf38e8f81c3936974c167219878edd, interactions with different AI services are vulnerable to admin-initiated SSRF attacks. Versions of the plugin that include commit 94ba0dadc2cf38e8f81c3936974c167219878edd contain a patch. As a workaround, one may disable the discourse-ai plugin.
Overview
- CVE ID
- CVE-2024-23654
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-02-21T20:28:12.939Z
- Last Modified Date
- 2024-02-21T20:28:12.939Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/discourse/discourse-ai/security/advisories/GHSA-32cj-rm2q-22cc | x_refsource_CONFIRM |
https://github.com/discourse/discourse-ai/commit/94ba0dadc2cf38e8f81c3936974c167219878edd | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-23654 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-23654 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-26 07:18:06 | Added to TrackCVE |