mirror of
https://github.com/discourse/discourse.git
synced 2026-08-01 17:18:15 -05:00
This only affects multisite Discourse instances (where multiple forums are served from a single application server). The vast majority of self-hosted Discourse forums do not fall into this category. On affected instances, this vulnerability could allow encrypted session cookies to be re-used between sites served by the same application instance.