CVE-2023-22740
- EPSS 0.38%
- Veröffentlicht 27.01.2023 01:15:08
- Zuletzt bearbeitet 21.11.2024 07:45:19
Discourse is an open source platform for community discussion. Versions prior to 3.1.0.beta1 (beta) (tests-passed) are vulnerable to Allocation of Resources Without Limits. Users can create chat drafts of an unlimited length, which can cause a denia...
CVE-2023-22739
- EPSS 0.38%
- Veröffentlicht 26.01.2023 21:18:13
- Zuletzt bearbeitet 21.11.2024 07:45:19
Discourse is an open source platform for community discussion. Versions prior to 3.0.1 (stable), 3.1.0.beta2 (beta), and 3.1.0.beta2 (tests-passed) are subject to Allocation of Resources Without Limits or Throttling. As there is no limit on data cont...
CVE-2023-22468
- EPSS 0.4%
- Veröffentlicht 26.01.2023 21:18:12
- Zuletzt bearbeitet 21.11.2024 07:44:51
Discourse is an open source platform for community discussion. Versions prior to 2.8.13 (stable), 3.0.0.beta16 (beta) and 3.0.0beta16 (tests-passed), are vulnerable to cross-site Scripting. A maliciously crafted URL can be included in a post to carry...
CVE-2023-22455
- EPSS 0.46%
- Veröffentlicht 05.01.2023 21:15:09
- Zuletzt bearbeitet 21.11.2024 07:44:50
Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 3.0.0.beta16 on the `beta` and `tests-passed` branches, tag descriptions, which can be updated by moderators, can be used for cross-site scr...
CVE-2022-46177
- EPSS 0.4%
- Veröffentlicht 05.01.2023 20:15:18
- Zuletzt bearbeitet 21.11.2024 07:30:16
Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 3.0.0.beta16 on the `beta` and `tests-passed` branches, when a user requests for a password reset link email, then changes their primary ema...
CVE-2023-22453
- EPSS 0.27%
- Veröffentlicht 05.01.2023 20:15:18
- Zuletzt bearbeitet 21.11.2024 07:44:50
Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 3.0.0.beta16 on the `beta` and `tests-passed` branches, the number of times a user posted in an arbitrary topic is exposed to unauthorized u...
CVE-2023-22454
- EPSS 0.29%
- Veröffentlicht 05.01.2023 20:15:18
- Zuletzt bearbeitet 21.11.2024 07:44:50
Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 3.0.0.beta16 on the `beta` and `tests-passed` branches, pending post titles can be used for cross-site scripting attacks. Pending posts can ...
CVE-2022-23546
- EPSS 0.07%
- Veröffentlicht 05.01.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 06:48:47
In version 2.9.0.beta14 of Discourse, an open-source discussion platform, maliciously embedded urls can leak an admin's digest of recent topics, possibly exposing private information. A patch is available for version 2.9.0.beta15. There are no known ...
CVE-2022-23548
- EPSS 0.52%
- Veröffentlicht 05.01.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 06:48:47
Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 2.9.0.beta16 on the `beta` and `tests-passed` branches, parsing posts can be susceptible to regular expression denial of service (ReDoS) att...
CVE-2022-23549
- EPSS 0.33%
- Veröffentlicht 05.01.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 06:48:47
Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 2.9.0.beta16 on the `beta` and `tests-passed` branches, users can create posts with raw body longer than the `max_length` site setting by in...