Information disclosure in Discourse - CVE-2019-15515

 

Information disclosure in Discourse - CVE-2019-15515

Published: August 30, 2019 / Updated: January 29, 2020


Vulnerability identifier: #VU20477
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-15515
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to software sends CSRF token in the query string. A remote attacker can gain access to the token via HTTP Referer header, bypass implemented CSRF protection mechanisms and perform CSRF attack


Affected software

Discourse
Gentoo Linux
Slackware Linux
Opensuse

How to mitigate CVE-2019-15515

Install update from vendor's website.

Discourse - update to 2.3.3

External References

Related Security Bulletins