Discourse is an open source discussion platform. Version before 3.6.2 and 3.6.0.beta2, default Cache-Control response header with value no-store, no-cache was missing from error responses. This may caused unintended caching of those responses by proxies potentially leading to cache poisoning attacks. This vulnerability is fixed in 3.6.2 and 3.6.0.beta2.
References
Configurations
Configuration 1 (hide)
|
History
03 Dec 2025, 16:31
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:discourse:discourse:*:*:*:*:beta:*:*:* cpe:2.3:a:discourse:discourse:3.6.0:beta1:*:*:beta:*:*:* cpe:2.3:a:discourse:discourse:*:*:*:*:stable:*:*:* |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
| References | () https://github.com/discourse/discourse/commit/3ea1b663c82c067e5ca778db846bad1e082ba6cd - Patch | |
| References | () https://github.com/discourse/discourse/commit/fd567af7bf5a15c70772021acbdf5d38487a31bc - Patch | |
| References | () https://github.com/discourse/discourse/security/advisories/GHSA-jp9x-wwv6-cv3j - Third Party Advisory | |
| First Time |
Discourse
Discourse discourse |
Information
Published : 2025-10-28 21:15
Updated : 2025-12-03 16:31
NVD link : CVE-2025-61598
Mitre link : CVE-2025-61598
CVE.ORG link : CVE-2025-61598
JSON object : View
Products Affected
discourse
- discourse
CWE
CWE-524
Use of Cache Containing Sensitive Information
