CVE-2023-37467 affects Discourse, the open source discussion platform. In versions prior to 3.1.0.beta7 on the beta and tests-passed branches, a Content Security Policy (CSP) nonce reuse issue could allow a cross-site scripting payload to bypass CSP protections for anonymous, unauthenticated users. The issue is specifically described as nonce reuse in the CSP implementation. The advisory notes that no concrete XSS vector was known at the time, but if an XSS injection point were present or later discovered, the reused nonce could permit script execution despite CSP. The issue does not apply to logged-in users, and the stable branch is not affected.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
gtm container id setting. More generally, reduce exposure by eliminating any potential XSS injection points and limiting use of configurations that rely on the affected CSP nonce behavior until patched.Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a Ruby proof-of-concept exploit for CVE-2023-37467, a Content Security Policy (CSP) nonce reuse vulnerability in Discourse versions prior to 3.1.1 stable and 3.2.0.beta2. The main file, 'CVE-2023-37467.rb', is a standalone script that tests a target Discourse instance for the presence of CSP, attempts to discover CSP nonces from various public and administrative pages, and checks if these nonces can be reused to inject JavaScript payloads, thereby bypassing CSP protections and enabling XSS attacks. The script is interactive and generates a report of findings, including discovered nonces and any confirmed vulnerabilities. The repository is structured simply, with the exploit code, a .gitignore, and a license file. No framework is used; the exploit is self-contained and written in Ruby, leveraging standard libraries for HTTP requests and HTML parsing. The attack vector is network-based, targeting web endpoints of a Discourse instance. The exploit requires the attacker to supply the base URL of the target, and it programmatically tests several common Discourse endpoints for nonce extraction and reuse.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.