Discourse DoS through Onebox favicon URL
CVE-2023-47120
Key Information:
What is CVE-2023-47120?
Discourse, an open-source community discussion platform, is affected by a memory depletion vulnerability that occurs when a site allows the use of excessively long favicon URLs in crafted posts. This issue can lead to significant Redis memory depletion, especially when multiple posts are drafted referencing such URLs. The vulnerability is present in the 'stable' branch versions 3.1.0 through 3.1.2 and 'beta' branch versions 3.1.0-beta6 through 3.2.0-beta2. The recommended mitigation is to upgrade to version 3.1.3 in the stable branch or 3.2.0.beta3 in the beta branches, as no workarounds are available to address the issue.
Affected Version(s)
discourse >= 3.1.0, < 3.1.3 < 3.1.0, 3.1.3
discourse >= 3.1.0.beta6, < 3.2.0.beta3 < 3.1.0.beta6, 3.2.0.beta3