Discourse vulnerability affects very long tag group names
CVE-2024-37299

7.5HIGH

Key Information:

Vendor
Discourse
Status
Vendor
CVE Published:
30 July 2024

Summary

A vulnerability in the Discourse discussion platform allows attackers to craft specific requests that submit excessively long tag group names. This can lead to a reduction in the availability of Discourse instances, impacting users and administrators. The issue has been addressed in versions 3.2.5 and 3.3.0.beta5, enhancing the platform's resilience against potential disruptions caused by input validation flaws.

Affected Version(s)

discourse < 3.2.5 < 3.2.5

discourse >= 3.3.0.beta1, < 3.3.0.beta5 < 3.3.0.beta1, 3.3.0.beta5

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.