PT-2022-26151 · Discourse · Discourse
Lowjomaxropublished
·
Published
2022-11-28
·
Updated
2024-03-06
·
CVE-2022-41921
CVSS v3.1
3.5
Low
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Discourse versions prior to 2.9.0.beta13
Description
Discourse is an open-source discussion platform. The issue allows users to post chat messages of an unlimited length, which can cause a denial of service for other users when huge amounts of text are posted.
Recommendations
For versions prior to 2.9.0.beta13, users should upgrade to version 2.9.0.beta13, where a limit on chat message length has been introduced to prevent the denial of service issue.
Exploit
Fix
DoS
Allocation of Resources Without Limits
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Discourse