We found results for “”
CVE-2023-41042
Date: September 15, 2023
Discourse is an open-source discussion platform. Prior to version 3.1.1 of the "stable" branch and version 3.2.0.beta1 of the "beta" and "tests-passed" branches, importing a remote theme loads their assets into memory without enforcing limits for file size or number of files. The issue is patched in version 3.1.1 of the "stable" branch and version 3.2.0.beta1 of the "beta" and "tests-passed" branches. There are no known workarounds.
Language: Ruby
Severity Score
Severity Score
Weakness Type (CWE)
Allocation of Resources Without Limits or Throttling
CWE-770CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | HIGH |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | NONE |
| Integrity (I): | NONE |
| Availability (A): | HIGH |
Vulnerabilities
Projects
Contact Us


