CVE-2021-43794
Published: 01 December 2021
Summary
CVE-2021-43794 is a medium-severity Externally Controlled Reference to a Resource in Another Sphere (CWE-610) vulnerability in Discourse Discourse. Its CVSS base score is 5.3 (Medium).
Operationally, ranked in the top 40.2% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2021-30690
Vulnerability details
Discourse is an open source discussion platform. In affected versions an attacker can poison the cache for anonymous (i.e. not logged in) users, such that the users are shown a JSON blob instead of the HTML page. This can lead…
more
to a partial denial-of-service. This issue is patched in the latest stable, beta and tests-passed versions of Discourse.
- CWE(s)
Related Threats
No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.
Affected Assets
Mitigating Controls
Likely Mitigating Controls AI
Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.
Limits impact of an externally controlled reference to a primary information resource by switching to an identified alternative.