CVE-2024-21655

Discourse is a platform for community discussion. For fields that are client editable, limits on sizes are not imposed. This allows a malicious actor to cause a Discourse instance to use excessive disk space and also often excessive bandwidth. The issue is patched 3.1.4 and 3.2.0.beta4.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:discourse:discourse:*:*:*:*:stable:*:*:*
cpe:2.3:a:discourse:discourse:3.2.0:beta1:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:3.2.0:beta2:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:3.2.0:beta3:*:*:beta:*:*:*

History

25 Jan 2024, 15:36

Type Values Removed Values Added
Summary
  • (es) Discourse es una plataforma para la discusión comunitaria. Para los campos que el cliente puede editar, no se imponen límites de tamaño. Esto permite que un actor malintencionado haga que una instancia de Discourse utilice espacio en disco excesivo y, a menudo, también ancho de banda excesivo. El problema está parcheado en 3.1.4 y 3.2.0.beta4.
CWE CWE-770
CPE cpe:2.3:a:discourse:discourse:3.2.0:beta3:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:3.2.0:beta2:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:*:*:*:*:stable:*:*:*
cpe:2.3:a:discourse:discourse:3.2.0:beta1:*:*:beta:*:*:*
First Time Discourse discourse
Discourse
References () https://github.com/discourse/discourse/security/advisories/GHSA-m5fc-94mm-38fx - () https://github.com/discourse/discourse/security/advisories/GHSA-m5fc-94mm-38fx - Vendor Advisory

12 Jan 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-12 21:15

Updated : 2024-01-25 15:36


NVD link : CVE-2024-21655

Mitre link : CVE-2024-21655

CVE.ORG link : CVE-2024-21655


JSON object : View

Products Affected

discourse

  • discourse
CWE
CWE-770

Allocation of Resources Without Limits or Throttling

CWE-400

Uncontrolled Resource Consumption