Collected research
Discourse Backup Disclosure: A Rails send_file Quirk
CVE-2024-53991 - Discourse Backup Disclosure: Rails send_file Quirk — ProjectDiscovery Blog
Explains how client-influenced file-delivery headers crossed the boundary between Rails/Rack and trusted Nginx routing, exposing Discourse backup files. This March 2025 analysis expands a December 2024 disclosure and describes the prerequisite of knowing a valid backup filename.
Record
- Document
- CVE-2024-53991 - Discourse Backup Disclosure: Rails send_file Quirk — ProjectDiscovery Blog
- Researcher
- Harsh Jaiswal and Rahul Maini
- Published by
- ProjectDiscovery
- Topic
- Other
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Harsh Jaiswal and Rahul Maini, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .