CVE-2021-41271

Discourse is a platform for community discussion. In affected versions a maliciously crafted request could cause an error response to be cached by intermediate proxies. This could cause a loss of confidentiality for some content. This issue is patched in the latest stable, beta and tests-passed versions of Discourse.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.8 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
GitHub_MCNA
4.8 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 50%
VendorProductVersion
discoursediscourse
𝑥
≤ 2.7.9
discoursediscourse
2.8.0:beta1
discoursediscourse
2.8.0:beta2
discoursediscourse
2.8.0:beta3
discoursediscourse
2.8.0:beta4
discoursediscourse
2.8.0:beta5
discoursediscourse
2.8.0:beta6
discoursediscourse
2.8.0:beta7
𝑥
= Vulnerable software versions