PT-2025-2994 · Discourse · Discourse

Taisehub

·

Published

2025-02-04

·

Updated

2025-09-26

·

CVE-2024-53851

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Discourse versions prior to the latest stable, beta and tests-passed versions
Description The issue is related to the endpoint for generating inline oneboxes for URLs, which did not enforce limits on the number of URLs accepted, allowing a malicious user to inflict a denial of service on some parts of the application. This can only be exploited by authenticated users.
Recommendations For versions prior to the latest stable, beta and tests-passed versions, update to the latest version to resolve the issue. For users unable to update, as a temporary workaround, turn off the enable inline onebox on all domains site setting and remove all entries from the allowed inline onebox domains site setting.

Exploit

Fix

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2024-53851
CVE-2024-53851
GHSA-49RV-574X-WGPC

Affected Products

Discourse