CVE-2021-41163 - CVE House
Back to Database
Status published Critical CVE-2021-41163

RCE via malicious SNS subscription payload

Vulnerability Description

Discourse is an open source platform for community discussion. In affected versions maliciously crafted requests could lead to remote code execution. This resulted from a lack of validation in subscribe_url values. This issue is patched in the latest stable, beta and tests-passed versions of Discourse. To workaround the issue without updating, requests with a path starting /webhooks/aws path could be blocked at an upstream proxy.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-41163

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

discourse
Vulnerable Versions:
tests-passed < 2.8.0.beta7, beta < 2.8.0.beta7, stable < 2.7.9

Timeline

Official Publish: October 20th, 2021
Last Modified: August 4th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Weaknesses (CWE)