We found results for “”
CVE-2023-38706
Date: September 15, 2023
Discourse is an open-source discussion platform. Prior to version 3.1.1 of the "stable" branch and version 3.2.0.beta1 of the "beta" and "tests-passed" branches, a malicious user can create an unlimited number of drafts with very long draft keys which may end up exhausting the resources on the server. The issue is patched in version 3.1.1 of the "stable" branch and version 3.2.0.beta1 of the "beta" and "tests-passed" branches. There are no known workarounds.
Language: Ruby
Severity Score
Severity Score
Weakness Type (CWE)
Allocation of Resources Without Limits or Throttling
CWE-770CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | LOW |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | NONE |
| Integrity (I): | NONE |
| Availability (A): | HIGH |
Vulnerabilities
Projects
Contact Us


