PT-2022-16903 · Discourse · Discourse

Pmusaraj

·

Published

2022-04-14

·

Updated

2024-03-06

·

CVE-2022-24824

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Discourse versions prior to the latest stable, beta and tests-passed versions
Description The issue affects Discourse, an open source platform for community discussion. An attacker can poison the cache for anonymous users, causing them to see the crawler view of the site instead of the HTML page, leading to a partial denial-of-service.
Recommendations Update to the latest stable, beta, or tests-passed version of Discourse to resolve the issue. As a temporary workaround, consider restricting access to anonymous users or implementing additional caching controls until a patch is applied.

Exploit

Fix

DoS

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2022-24824
CVE-2022-24824
GHSA-46V9-3JC4-F53W

Affected Products

Discourse