6.5

CVE-2023-38706

Exploit

Discourse vulnerable to DoS via drafts

Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 of the `beta` and `tests-passed` branches, a malicious user can create an unlimited number of drafts with very long draft keys which may end up exhausting the resources on the server. The issue is patched in version 3.1.1 of the `stable` branch and version 3.2.0.beta1 of the `beta` and `tests-passed` branches. There are no known workarounds.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Discourse ≫ Discourse SwEdition beta Version < 3.1.0
Discourse ≫ Discourse SwEdition stable Version <= 3.1.0
Discourse ≫ Discourse Version 3.1.0 Update beta1 SwEdition beta
Discourse ≫ Discourse Version 3.1.0 Update beta2 SwEdition beta
Discourse ≫ Discourse Version 3.1.0 Update beta3 SwEdition beta
Discourse ≫ Discourse Version 3.1.0 Update beta5 SwEdition beta
Discourse ≫ Discourse Version 3.1.0 Update beta6 SwEdition beta
Discourse ≫ Discourse Version 3.1.0 Update beta7 SwEdition beta
Discourse ≫ Discourse Version 3.1.0 Update beta8 SwEdition beta
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.64% 0.457
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
security-advisories@github.com 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-770 Allocation of Resources Without Limits or Throttling

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

https://github.com/discourse/discourse/security/advisories/GHSA-7wpp-4pqg-gvp8
Vendor Advisory
Exploit