icon

We found results for “

CVE-2023-38498

Date: July 28, 2023

Discourse is an open source discussion platform. Prior to version 3.0.6 of the "stable" branch and version 3.1.0.beta7 of the "beta" and "tests-passed" branches, a malicious user can prevent the defer queue from proceeding promptly on sites hosted in the same multisite installation. The issue is patched in version 3.0.6 of the "stable" branch and version 3.1.0.beta7 of the "beta" and "tests-passed" branches. There are no known workarounds for this vulnerability. Users of multisite configurations should upgrade.

Language: Ruby

Severity Score

Severity Score

Weakness Type (CWE)

Uncontrolled Resource Consumption

CWE-400

Allocation of Resources Without Limits or Throttling

CWE-770

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): LOW
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): NONE
Integrity (I): NONE
Availability (A): LOW

Do you need more information?

Contact Us