CVE-2021-41271

EUVD-2021-28307
Discourse is a platform for community discussion. In affected versions a maliciously crafted request could cause an error response to be cached by intermediate proxies. This could cause a loss of confidentiality for some content. This issue is patched in the latest stable, beta and tests-passed versions of Discourse.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.8 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
GitHub_MCNA
4.8 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 51%
Affected Products (NVD)
VendorProductVersion
discoursediscourse
𝑥
≤ 2.7.9
discoursediscourse
2.8.0:beta1
discoursediscourse
2.8.0:beta2
discoursediscourse
2.8.0:beta3
discoursediscourse
2.8.0:beta4
discoursediscourse
2.8.0:beta5
discoursediscourse
2.8.0:beta6
discoursediscourse
2.8.0:beta7
𝑥
= Vulnerable software versions