CVE-2025-58055 (CNNVD-202510-026)
中文标题:
Discourse 安全漏洞
英文标题:
Discourse AI Suggestions Contain Insecure Direct Object Reference
漏洞描述
中文描述:
Discourse是Discourse开源的一套开源的社区讨论平台。该平台包括社区、电子邮件和聊天室等功能。 Discourse 3.5.0及之前版本存在安全漏洞,该漏洞源于AI建议端点未正确验证topic_id参数,可能导致信息泄露。
英文描述:
Discourse is an open-source community discussion platform. In versions 3.5.0 and below, the Discourse AI suggestion endpoints for topic “Title”, “Category”, and “Tags” allowed authenticated users to extract information about topics that they weren’t authorized to access. By modifying the “topic_id” value in API requests to the AI suggestion endpoints, users could target specific restricted topics. The AI model’s responses then disclosed information that the authenticated user couldn’t normally access. This issue is fixed in version 3.5.1. To workaround this issue, users can restrict group access to the AI helper feature through the "composer_ai_helper_allowed_groups" and "post_ai_helper_allowed_groups" site settings.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| discourse | discourse | < 3.5.1 | - | - |
cpe:2.3:a:discourse:discourse:<_3.5.1:*:*:*:*:*:*:*
|
| discourse | discourse | * | - | - |
cpe:2.3:a:discourse:discourse:*:*:*:*:stable:*:*:*
|
| discourse | discourse | 3.6.0 | - | - |
cpe:2.3:a:discourse:discourse:3.6.0:beta1:*:*:beta:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
cve.org
nvd.nist.gov
nvd.nist.gov
CVSS评分详情
3.1 (cna)
MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2025-58055 |
2025-11-11 15:23:30 | 2025-11-11 07:40:45 |
| NVD | nvd_CVE-2025-58055 |
2025-11-11 15:01:04 | 2025-11-11 07:48:32 |
| CNNVD | cnnvd_CNNVD-202510-026 |
2025-11-11 15:12:29 | 2025-11-11 08:00:15 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 其他
- cnnvd_id: 未提取 -> CNNVD-202510-026
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 1 -> 3
- references_count: 2 -> 4
- data_sources: ['cve'] -> ['cve', 'nvd']