PT-2022-11919 · Discourse · Discourse

Samsaffron

·

Published

2022-01-04

·

Updated

2024-03-06

·

CVE-2021-43850

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Discourse versions prior to 2.8.0.beta10 Discourse versions prior to 2.7.12
Description The issue affects Discourse, an open source platform for community discussion, where admin users can trigger a Denial of Service attack via the "/message-bus/ diagnostics" API endpoint. This vulnerability has a greater impact on multisite Discourse instances, where any admin user on any of the forums can visit the "/message-bus/ diagnostics" path.
Recommendations For versions prior to 2.8.0.beta10, upgrade to 2.8.0.beta10 or later. For versions prior to 2.7.12, upgrade to 2.7.12 or later.

Exploit

Fix

DoS

RCE

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2021-43850
CVE-2021-43850
GHSA-59JR-PJ65-QMVR

Affected Products

Discourse