PT-2022-16903 · Discourse · Discourse
Pmusaraj
·
Published
2022-04-14
·
Updated
2024-03-06
·
CVE-2022-24824
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Discourse versions prior to the latest stable, beta and tests-passed versions
Description
The issue affects Discourse, an open source platform for community discussion. An attacker can poison the cache for anonymous users, causing them to see the crawler view of the site instead of the HTML page, leading to a partial denial-of-service.
Recommendations
Update to the latest stable, beta, or tests-passed version of Discourse to resolve the issue.
As a temporary workaround, consider restricting access to anonymous users or implementing additional caching controls until a patch is applied.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Discourse