PT-2024-21637 · Discourse · Discourse

Nattsw

·

Published

2024-03-15

·

Updated

2025-08-26

·

CVE-2024-27085

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Discourse versions prior to the latest version
Description The issue affects Discourse, an open source platform for community discussion. Users allowed to invite others can inject arbitrarily large data in parameters used in the invite route.
Recommendations For versions prior to the latest version, upgrade to the latest version. As a temporary workaround for users unable to upgrade, consider disabling invites or restrict access to them using the invite allowed groups site setting.

Exploit

Fix

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2024-27085
CVE-2024-27085
GHSA-CVP5-H7P8-MJJ6

Affected Products

Discourse