Discourse DoS through Onebox favicon URL
CVE-2023-47120

7.5HIGH

Key Information:

Vendor
Discourse
Status
Vendor
CVE Published:
10 November 2023

Summary

Discourse, an open-source community discussion platform, is affected by a memory depletion vulnerability that occurs when a site allows the use of excessively long favicon URLs in crafted posts. This issue can lead to significant Redis memory depletion, especially when multiple posts are drafted referencing such URLs. The vulnerability is present in the 'stable' branch versions 3.1.0 through 3.1.2 and 'beta' branch versions 3.1.0-beta6 through 3.2.0-beta2. The recommended mitigation is to upgrade to version 3.1.3 in the stable branch or 3.2.0.beta3 in the beta branches, as no workarounds are available to address the issue.

Affected Version(s)

discourse >= 3.1.0, < 3.1.3 < 3.1.0, 3.1.3

discourse >= 3.1.0.beta6, < 3.2.0.beta3 < 3.1.0.beta6, 3.2.0.beta3

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.