CVE-2024-47773

Anonymous cache poisoning via XHR requests in Discourse

Discourse is an open source platform for community discussion. An attacker can make several XHR requests until the cache is poisoned with a response without any preloaded data. This issue only affects anonymous visitors of the site. This problem has been patched in the latest version of Discourse. Users are advised to upgrade. Users unable to upgrade should disable anonymous cache by setting the `DISCOURSE_DISABLE_ANON_CACHE` environment variable to a non-empty value.


We have discovered 1,268 live websites that are affected by CVE-2024-47773.

Run a Free Instant Scan




Affected Software

Product  Discourse
Category Message Boards
Vulnerable Domains1,268 live websites (27% of Discourse install base)
Vulnerable Versions
  • from 0 through 3.3.2
Vulnerable Versions Count49 versions ( 75% of all versions)


Common Weakness Enumeration

CWE-610 Externally Controlled Reference to a Resource in Another Sphere



Details

  • Published - Oct 8, 2024
  • Updated - Oct 8, 2024

Website Distribution by Country

Number of websites using CVE-2024-47773
United States783 websites



Germany123 websites
France57 websites
Singapore34 websites
China29 websites
GB23 websites
Russia23 websites
Japan19 websites
Brazil18 websites
Canada14 websites

Website Distribution by TLD

Number of websites using CVE-2024-47773
.com529 websites
.org193 websites
.io59 websites
.net56 websites
.de30 websites
.ru20 websites
.fr18 websites
.co16 websites
.eu15 websites
.com.br11 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-47773

Top websites that are affected by CVE-2024-47773. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.********.com United States**,***
*********.***************.com United States**,***
**************.org United States***,***
*****.*******.com United States***,***
*****.******.com United States***,***
*********.**********.de Germany***,***
*****.******.cloud United States***,***
**********.com United States***,***
*****.works United States***,***
*********.**********.io United States***,***
See full domain list

FAQ

CVE-2024-47773 is Externally Controlled Reference to a Resource in Another Sphere in Discourse
A total of 1,268 websites have been identified as vulnerable to CVE-2024-47773, based on global website indexing conducted by WebTechSurvey.
The Discourse is affected by the CVE-2024-47773 vulnerability.
Discourse versions up to 3.3.2 are vulnerable to CVE-2024-47773.
CVE-2024-47773 is resolved in version 3.3.2 of Discourse.