PT-2022-6368 · Discourse+1 · Discourse+1
Jomaxro
·
Published
2022-08-01
·
Updated
2024-03-06
·
CVE-2022-31182
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Discourse versions prior to the latest stable, beta, and tests-passed versions
Description
The issue is related to a maliciously crafted request for static assets that could cause error responses to be cached by Discourse's default NGINX proxy configuration. This could lead to a denial of service. There are no known workarounds for this issue.
Recommendations
Upgrade to the latest stable, beta, or tests-passed version of Discourse to resolve the issue.
As a temporary workaround, consider correcting the NGINX configuration to prevent error responses from being cached.
Exploit
Fix
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Discourse
Nginx