CVE-2023-41042
- EPSS 0.51%
- Veröffentlicht 15.09.2023 20:15:10
- Zuletzt bearbeitet 21.11.2024 08:20:26
Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 of the `beta` and `tests-passed` branches, importing a remote theme loads their assets into memory without enforcing limits for fil...
CVE-2023-41043
- EPSS 0.51%
- Veröffentlicht 15.09.2023 20:15:10
- Zuletzt bearbeitet 21.11.2024 08:20:26
Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 of the `beta` and `tests-passed` branches, a malicious admin could create extremely large icons sprites, which would then be cached...
CVE-2023-38706
- EPSS 0.64%
- Veröffentlicht 15.09.2023 20:15:09
- Zuletzt bearbeitet 21.11.2024 08:14:05
Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 of the `beta` and `tests-passed` branches, a malicious user can create an unlimited number of drafts with very long draft keys whic...
CVE-2023-38498
- EPSS 0.58%
- Veröffentlicht 28.07.2023 16:15:12
- Zuletzt bearbeitet 21.11.2024 08:13:41
Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, a malicious user can prevent the defer queue from proceeding promptly on sites hosted in...
CVE-2023-38684
- EPSS 0.53%
- Veröffentlicht 28.07.2023 16:15:12
- Zuletzt bearbeitet 21.11.2024 08:14:02
Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, in multiple controller actions, Discourse accepts limit params but does not impose any u...
CVE-2023-38685
- EPSS 0.39%
- Veröffentlicht 28.07.2023 16:15:12
- Zuletzt bearbeitet 21.11.2024 08:14:03
Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, information about restricted-visibility topic tags could be obtained by unauthorized use...
CVE-2023-37904
- EPSS 0.24%
- Veröffentlicht 28.07.2023 16:15:11
- Zuletzt bearbeitet 21.11.2024 08:12:26
Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, more users than permitted could be created from invite links. The issue is patched in ve...
CVE-2023-37906
- EPSS 0.45%
- Veröffentlicht 28.07.2023 16:15:11
- Zuletzt bearbeitet 21.11.2024 08:12:26
Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, a malicious user can edit a post in a topic and cause a DoS with a carefully crafted edi...
CVE-2023-37467
- EPSS 0.32%
- Veröffentlicht 28.07.2023 15:15:10
- Zuletzt bearbeitet 21.11.2024 08:11:46
Discourse is an open source discussion platform. Prior to version 3.1.0.beta7 of the `beta` and `tests-passed` branches, a CSP (Content Security Policy) nonce reuse vulnerability was discovered could allow cross-site scripting (XSS) attacks to bypass...
CVE-2023-36466
- EPSS 0.35%
- Veröffentlicht 14.07.2023 22:15:09
- Zuletzt bearbeitet 21.11.2024 08:09:46
Discourse is an open source discussion platform. When editing a topic, there is a vulnerability that enables a user to bypass the topic title validations for things like title length, number of emojis in title and blank topic titles. The issue is pat...