PT-2023-27755 · Discourse · Discourse

Jomaxro

·

Published

2023-09-15

·

Updated

2024-03-06

·

CVE-2023-41042

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Discourse versions prior to 3.1.1 Discourse version 3.2.0.beta1 and earlier in the beta and tests-passed branches
Description Discourse is an open-source discussion platform. Importing a remote theme loads their assets into memory without enforcing limits for file size or number of files.
Recommendations For versions prior to 3.1.1, update to version 3.1.1 or later. For version 3.2.0.beta1 and earlier in the beta and tests-passed branches, update to version 3.2.0.beta1 or later.

Exploit

Fix

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2023-41042
CVE-2023-41042
GHSA-2FQ5-X3MM-V254

Affected Products

Discourse