PT-2023-22804 · Discourse · Discourse

Nattsw

·

Published

2023-04-18

·

Updated

2024-03-06

·

CVE-2023-30606

CVSS v3.1

4.2

Medium

VectorAV:N/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Discourse versions prior to the latest stable, beta and tests-passed versions
Description Discourse is an open source platform for community discussion. In affected versions, a user logged as an administrator can call arbitrary methods on the SiteSetting class, notably #clear cache! and #notify changed!, which when done on a multisite instance, can affect the entire cluster resulting in a denial of service. Users not running in multisite environments are not affected.
Recommendations For all affected versions of Discourse, upgrade to the latest stable, beta, or tests-passed version to resolve the issue. As a temporary workaround, consider restricting administrative access to trusted users only until the upgrade can be applied.

Exploit

Fix

DoS

Incorrect Permission

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2023-30606
CVE-2023-30606
GHSA-JJ93-W3MV-3JVV

Affected Products

Discourse