PT-2023-3566 · Discourse · Discourse

Jomaxro

·

Published

2023-06-21

·

Updated

2024-03-06

·

CVE-2023-36466

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions Discourse versions prior to the latest stable, beta and tests-passed version
Description The issue is related to insufficient input validation when processing topic titles, allowing a remote attacker to impact the integrity and availability of protected information. The vulnerability enables a user to bypass topic title validations, such as title length, number of emojis in the title, and blank topic titles, when editing a topic.
Recommendations For versions prior to the latest stable, beta and tests-passed version, update to the latest stable, beta or tests-passed version to resolve the issue. As a temporary workaround, consider restricting the ability to edit topic titles until the update is applied.

Exploit

Fix

RCE

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2023-03787
BIT-DISCOURSE-2023-36466
CVE-2023-36466
GHSA-4HJH-WG43-P932

Affected Products

Discourse