4.9
CVE-2024-38360
- EPSS 0.47%
- Veröffentlicht 15.07.2024 20:15:03
- Zuletzt bearbeitet 26.08.2025 19:13:33
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
Denial of service via Watched Words in Discourse
Discourse is an open source platform for community discussion. In affected versions by creating replacement words with an almost unlimited number of characters, a moderator can reduce the availability of a Discourse instance. This issue has been addressed in stable version 3.2.3 and in current betas. Users are advised to upgrade. Users unable to upgrade may manually remove the long watched words either via SQL or Rails console.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.47% | 0.369 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 4.9 | 1.2 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
|
CWE-400 Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
https://github.com/discourse/discourse/commit/7b53e610c17e38be982dffefa4e5b5a709a3b990
https://github.com/discourse/discourse/security/advisories/GHSA-68pm-hm8x-pq2p