PT-2022-6368 · Discourse+1 · Discourse+1

Jomaxro

·

Published

2022-08-01

·

Updated

2024-03-06

·

CVE-2022-31182

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Discourse versions prior to the latest stable, beta, and tests-passed versions
Description The issue is related to a maliciously crafted request for static assets that could cause error responses to be cached by Discourse's default NGINX proxy configuration. This could lead to a denial of service. There are no known workarounds for this issue.
Recommendations Upgrade to the latest stable, beta, or tests-passed version of Discourse to resolve the issue. As a temporary workaround, consider correcting the NGINX configuration to prevent error responses from being cached.

Exploit

Fix

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-01058
BIT-DISCOURSE-2022-31182
CVE-2022-31182
GHSA-4FF8-3J78-W6PP

Affected Products

Discourse
Nginx