# Discourse Vulnerability \[False Positive\]

**URL:** https://meta.discourse.org/t/discourse-vulnerability-false-positive/119958
**Category:** Support
**Created:** [10.Июнь.2019 20:59:38 UTC](https://meta.discourse.org/t/discourse-vulnerability-false-positive/119958 "2019-06-10T20:59:38Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![arcreigh](https://avatars.discourse-cdn.com/v4/letter/a/71e660/32.png) [@arcreigh](https://meta.discourse.org/u/arcreigh)
#### Post date: [10.Июнь.2019 20:59:38 UTC](https://meta.discourse.org/t/discourse-vulnerability-false-positive/119958/1 "2019-06-10T20:59:38Z")

</div>

It appears there is a CVE out for the discourse admin page. 100005 DotNetNuke - File Inclusion - CVE:CVE-2018-9126, CVE:CVE-2011-1892.

Cloudflare was triggered while trying to update my discourse installation it 403’d this URI /admin/docker/latest?path=%2Fvar%2Fwww%2Fdiscourse&version=c093fa0&branch=origin%2Ftests-passed

This prevented update checking to continue. Whitelisting my IP in cloudflare resolved this issue.

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [10.Июнь.2019 21:12:43 UTC](https://meta.discourse.org/t/discourse-vulnerability-false-positive/119958/2 "2019-06-10T21:12:43Z")

</div>

Neither of these are related to Discourse. Recommend you take this up with cloudflare and disable the orange cloudflare acceleration button

---

<div class="post-metadata">

### Author: ![arcreigh](https://avatars.discourse-cdn.com/v4/letter/a/71e660/32.png) [@arcreigh](https://meta.discourse.org/u/arcreigh)
#### Post date: [10.Июнь.2019 21:28:59 UTC](https://meta.discourse.org/t/discourse-vulnerability-false-positive/119958/3 "2019-06-10T21:28:59Z")

</div>

Cool deal I’ll flag this as a false positive on my end and move on thanks Sam!

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [10.Июнь.2019 21:37:28 UTC](https://meta.discourse.org/t/discourse-vulnerability-false-positive/119958/4 "2019-06-10T21:37:28Z")

</div>


