Discourse DoS through Onebox favicon URL
CVE-2023-47120
Summary
Discourse, an open-source community discussion platform, is affected by a memory depletion vulnerability that occurs when a site allows the use of excessively long favicon URLs in crafted posts. This issue can lead to significant Redis memory depletion, especially when multiple posts are drafted referencing such URLs. The vulnerability is present in the 'stable' branch versions 3.1.0 through 3.1.2 and 'beta' branch versions 3.1.0-beta6 through 3.2.0-beta2. The recommended mitigation is to upgrade to version 3.1.3 in the stable branch or 3.2.0.beta3 in the beta branches, as no workarounds are available to address the issue.
Affected Version(s)
discourse >= 3.1.0, < 3.1.3 < 3.1.0, 3.1.3
discourse >= 3.1.0.beta6, < 3.2.0.beta3 < 3.1.0.beta6, 3.2.0.beta3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved