PT-2023-27524 · Discourse · Discourse

Jomaxro

·

Published

2023-09-15

·

Updated

2024-03-06

·

CVE-2023-40588

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Discourse versions prior to 3.1.1 Discourse version 3.2.0.beta1 and earlier in the beta and tests-passed branches
Description A malicious user could add a 2FA or security key with a carefully crafted name to their account, causing a denial of service for other users.
Recommendations For versions prior to 3.1.1, update to version 3.1.1 or later. For version 3.2.0.beta1 and earlier in the beta and tests-passed branches, update to version 3.2.0.beta1 or later.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2023-40588
CVE-2023-40588
GHSA-2HG5-3XM3-9VVX

Affected Products

Discourse