icon

We found results for “

CVE-2023-40588

Date: September 15, 2023

Discourse is an open-source discussion platform. Prior to version 3.1.1 of the "stable" branch and version 3.2.0.beta1 of the "beta" and "tests-passed" branches, a malicious user could add a 2FA or security key with a carefully crafted name to their account and cause a denial of service for other users. The issue is patched in version 3.1.1 of the "stable" branch and version 3.2.0.beta1 of the "beta" and "tests-passed" branches. There are no known workarounds.

Language: Ruby

Severity Score

Severity Score

Weakness Type (CWE)

Allocation of Resources Without Limits or Throttling

CWE-770

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): LOW
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): NONE
Integrity (I): NONE
Availability (A): HIGH

Do you need more information?

Contact Us