← Back to browse · API

CVE-2021-41163

Severity
CRITICAL
CVSS
10.0
EPSS
0.19812
Risk score
46.93
CISA KEV
No
PoC
No
Published
2021-10-20
Modified
2024-08-04
First seen
2026-08-07
Aliases
EUVD-2021-28273
Products
discourse:discourse beta < 2.8.0.beta7, discourse:discourse stable < 2.7.9, discourse:discourse tests-passed < 2.8.0.beta7
Sources
euvd EUVD-2021-28273

Description

Discourse is an open source platform for community discussion. In affected versions maliciously crafted requests could lead to remote code execution. This resulted from a lack of validation in subscribe_url values. This issue is patched in the latest stable, beta and tests-passed versions of Discourse. To workaround the issue without updating, requests with a path starting /webhooks/aws path could be blocked at an upstream proxy.

References