PT-2023-27524 · Discourse · Discourse

·

CVE-2023-40588

·

Published

2023-09-15

·

Updated

2024-03-06

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Discourse versions prior to 3.1.1 Discourse version 3.2.0.beta1 and earlier in the beta and tests-passed branches
Description A malicious user could add a 2FA or security key with a carefully crafted name to their account, causing a denial of service for other users.
Recommendations For versions prior to 3.1.1, update to version 3.1.1 or later. For version 3.2.0.beta1 and earlier in the beta and tests-passed branches, update to version 3.2.0.beta1 or later.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2023-40588
CVE-2023-40588
GHSA-2HG5-3XM3-9VVX

Affected Products

Discourse