PT-2024-30658 · Discourse · Discourse
Nattsw
·
Published
2024-10-07
·
Updated
2025-09-25
·
CVE-2024-43789
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Discourse versions prior to the latest version
Description
Discourse is an open source platform for community discussion. A user can create a post with many replies, and then attempt to fetch them all at once. This can potentially reduce the availability of a Discourse instance.
Recommendations
Upgrade to the latest version of Discourse.
As a temporary workaround, consider restricting the number of replies that can be fetched at once to minimize the risk of exploitation.
Exploit
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Discourse