GHSA-xmgj-5fh3-xjmm · Severity: medium · Ecosystem: rubygems — Path traversal when MessageBus::Diagnostics is enabled
message_bus is a messaging bus for Ruby processes and web clients. In versions prior to 3.3.7 users who deployed message bus with diagnostics features enabled (default off) are vulnerable to a path traversal bug, which could lead to disclosure of secret information on a machine if an unintended user were to gain access to the diagnostic route. The impact is also greater if there is no proxy for your web application as the number of steps up the directories is not bounded. For deployments which uses a proxy, the impact varies. For example, If a request goes through a proxy like Nginx with `merge_slashes` enabled, the number of steps up the directories that can be read is limited to 3 levels. This issue has been patched in version 3.3.7. Users unable to upgrade should ensure that MessageBus::Diagnostics is disabled.
Conclusion & alert: CVE-2021-43840 is rated Moderate Risk (46/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 1.87%). Core evidence: EPSS rose +1.65% over the last day, indicating growing attacker interest. Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.22% | 1.87% | +1.65% |
| 2 | 2025-03-30 | 0.43% | 0.22% | -0.21% |
| 3 | 2025-03-29 | — | 0.43% | — |
Full EPSS history (7 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 4.4 | 3.1 | MEDIUM |
|
0.7 | 3.6 | [email protected] |
| 6.5 | 3.1 | MEDIUM |
|
2.8 | 3.6 | [email protected] |
| 3.5 | 2.0 | LOW |
|
6.8 | 2.9 | [email protected] |
GHSA-xmgj-5fh3-xjmm · Severity: medium · Ecosystem: rubygems — Path traversal when MessageBus::Diagnostics is enabled
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| discourse | message_bus | < 3.3.7 | cpe:2.3:a:discourse:message_bus:*:*:*:*:*:ruby:*:* |
| URL | Tags |
|---|---|
| https://github.com/discourse/message_bus/commit/9b6deee01ed474c7e9b5ff65a06bb0447b4db2ba | Patch Third Party Advisory |
| https://github.com/discourse/message_bus/security/advisories/GHSA-xmgj-5fh3-xjmm | Third Party Advisory |