PT-2024-26391 · Discourse · Discourse

Ry0Tak

·

Published

2024-07-03

·

Updated

2024-07-09

·

CVE-2024-35227

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Discourse versions prior to 3.2.3 on the stable branch Discourse versions prior to 3.3.0.beta3 on the tests-passed branch
Description The issue affects Discourse, an open-source discussion platform, where Oneboxing against a carefully crafted malicious URL can reduce the availability of a Discourse instance. This is due to improper input validation, posing risks to data integrity. There are no known workarounds available for this issue.
Recommendations For Discourse versions prior to 3.2.3 on the stable branch, update to version 3.2.3 or later. For Discourse versions prior to 3.3.0.beta3 on the tests-passed branch, update to version 3.3.0.beta3 or later.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2024-35227
CVE-2024-35227
GHSA-664F-XWJW-752C

Affected Products

Discourse