Vulnerability record · CVE-2021-41163 · published 20 October 2021
CVE-2021-41163: Discourse injection vulnerability
Discourse · Discourse
Discourse is an open source platform for community discussion. In affected versions maliciously crafted requests could lead to remote code execution. This resulted from a lack of validation in subscribe_url values. This issue is patched in the latest stable, beta and tests-passed versions of Discourse. To workaround the issue without updating, requests with a path starting /webhooks/aws path could be blocked at an upstream proxy.
Description
Discourse is an open source platform for community discussion. In affected versions maliciously crafted requests could lead to remote code execution. This resulted from a lack of validation in subscribe_url values. This issue is patched in the latest stable, beta and tests-passed versions of Discourse. To workaround the issue without updating, requests with a path starting /webhooks/aws path could be blocked at an upstream proxy.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/discourse/discourse/commit/fa3c46cf079d28b086fe1025349bb00223a5d5e9 | PatchThird Party Advisory |
| https://github.com/discourse/discourse/security/advisories/GHSA-jcjx-pvpc-qgwq | Third Party Advisory |
| https://github.com/discourse/discourse/commit/fa3c46cf079d28b086fe1025349bb00223a5d5e9 | PatchThird Party Advisory |
| https://github.com/discourse/discourse/security/advisories/GHSA-jcjx-pvpc-qgwq | Third Party Advisory |
Track CVE-2021-41163 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-41163), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.