PT-2025-2994 · Discourse · Discourse
Taisehub
·
Published
2025-02-04
·
Updated
2025-09-26
·
CVE-2024-53851
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Discourse versions prior to the latest stable, beta and tests-passed versions
Description
The issue is related to the endpoint for generating inline oneboxes for URLs, which did not enforce limits on the number of URLs accepted, allowing a malicious user to inflict a denial of service on some parts of the application. This can only be exploited by authenticated users.
Recommendations
For versions prior to the latest stable, beta and tests-passed versions, update to the latest version to resolve the issue.
For users unable to update, as a temporary workaround, turn off the
enable inline onebox on all domains site setting and remove all entries from the allowed inline onebox domains site setting.Exploit
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Discourse