PT-2024-27959 · Discourse · Discourse

Nattsw

·

Published

2024-07-15

·

Updated

2025-08-26

·

CVE-2024-38360

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Discourse versions prior to 3.2.3
Description Discourse is an open source platform for community discussion. In affected versions, by creating replacement words with an almost unlimited number of characters, a moderator can reduce the availability of a Discourse instance.
Recommendations For versions prior to 3.2.3, upgrade to stable version 3.2.3 or a current beta to address the issue. As a temporary workaround for users unable to upgrade, manually remove the long watched words either via SQL or Rails console.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2024-38360
CVE-2024-38360
GHSA-68PM-HM8X-PQ2P

Affected Products

Discourse