Discourse

Discourse

188 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.32%
  • Veröffentlicht 16.10.2023 22:15:12
  • Zuletzt bearbeitet 21.11.2024 08:24:49

Discourse is an open source platform for community discussion. Attackers with details specific to a poll in a topic can use the `/polls/grouped_poll_results` endpoint to view the content of options in the poll and the number of votes for groups of po...

  • EPSS 0.21%
  • Veröffentlicht 16.10.2023 22:15:12
  • Zuletzt bearbeitet 21.11.2024 08:25:47

Discourse is an open source platform for community discussion. A malicious request can cause production log files to quickly fill up and thus result in the server running out of disk space. This problem has been patched in the 3.1.1 stable and 3.2.0....

  • EPSS 0.28%
  • Veröffentlicht 16.10.2023 22:15:12
  • Zuletzt bearbeitet 21.11.2024 08:25:48

Discourse is an open source platform for community discussion. User summaries are accessible for anonymous users even when `hide_user_profiles_from_public` is enabled. This problem has been patched in the 3.1.1 stable and 3.2.0.beta2 version of Disco...

  • EPSS 7.39%
  • Veröffentlicht 16.10.2023 22:15:12
  • Zuletzt bearbeitet 21.11.2024 08:26:24

Discourse is an open source platform for community discussion. New chat messages can be read by making an unauthenticated POST request to MessageBus. This issue is patched in the 3.1.1 stable and 3.2.0.beta2 versions of Discourse. Users are advised t...

  • EPSS 0.22%
  • Veröffentlicht 16.10.2023 21:15:11
  • Zuletzt bearbeitet 21.11.2024 08:26:26

Discourse is an open source community platform. In affected versions any user can create a topic and add arbitrary custom fields to a topic. The severity of this vulnerability depends on what plugins are installed and how the plugins uses topic custo...

  • EPSS 0.09%
  • Veröffentlicht 15.09.2023 20:15:10
  • Zuletzt bearbeitet 21.11.2024 08:19:46

Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 of the `beta` and `tests-passed` branches, a malicious user could add a 2FA or security key with a carefully crafted name to their ...

  • EPSS 0.05%
  • Veröffentlicht 15.09.2023 20:15:10
  • Zuletzt bearbeitet 21.11.2024 08:20:26

Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 of the `beta` and `tests-passed` branches, importing a remote theme loads their assets into memory without enforcing limits for fil...

  • EPSS 0.09%
  • Veröffentlicht 15.09.2023 20:15:10
  • Zuletzt bearbeitet 21.11.2024 08:20:26

Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 of the `beta` and `tests-passed` branches, a malicious admin could create extremely large icons sprites, which would then be cached...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 15.09.2023 20:15:09
  • Zuletzt bearbeitet 21.11.2024 08:14:05

Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 of the `beta` and `tests-passed` branches, a malicious user can create an unlimited number of drafts with very long draft keys whic...

  • EPSS 0.15%
  • Veröffentlicht 28.07.2023 16:15:12
  • Zuletzt bearbeitet 21.11.2024 08:13:41

Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, a malicious user can prevent the defer queue from proceeding promptly on sites hosted in...