PT-2024-27456 · Discourse · Discourse

Nattsw

·

Published

2024-07-30

·

Updated

2024-09-11

·

CVE-2024-37299

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Discourse versions prior to 3.2.5 Discourse versions prior to 3.3.0.beta5
Description The issue concerns crafting requests to submit very long tag group names, which can reduce the availability of a Discourse instance.
Recommendations For versions prior to 3.2.5, update to version 3.2.5 to resolve the issue. For versions prior to 3.3.0.beta5, update to version 3.3.0.beta5 to resolve the issue.

Exploit

Fix

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2024-37299
CVE-2024-37299
GHSA-4J6H-9PJP-5476

Affected Products

Discourse