Discourse

Discourse

252 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.59%
  • Veröffentlicht 14.07.2023 22:15:09
  • Zuletzt bearbeitet 21.11.2024 08:10:39

Discourse is an open source discussion platform. In affected versions a request to create or update custom sidebar section can cause a denial of service. This issue has been patched in commit `52b003d915`. Users are advised to upgrade. There are no k...

  • EPSS 0.35%
  • Veröffentlicht 13.07.2023 21:15:08
  • Zuletzt bearbeitet 21.11.2024 08:09:47

Discourse is an open source discussion platform. A CSP (Content Security Policy) nonce reuse vulnerability could allow XSS attacks to bypass CSP protection. There are no known XSS vectors at the moment, but should one be discovered, this vulnerabilit...

  • EPSS 0.32%
  • Veröffentlicht 13.06.2023 22:15:09
  • Zuletzt bearbeitet 21.11.2024 08:01:28

Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passed` branches, if a site has modified their general category permissions, they could be set back to the...

  • EPSS 0.36%
  • Veröffentlicht 13.06.2023 22:15:09
  • Zuletzt bearbeitet 21.11.2024 08:02:38

Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passed` branches, the lack of restrictions on the iFrame tag makes it easy for an attacker to exploit the ...

  • EPSS 0.42%
  • Veröffentlicht 13.06.2023 22:15:09
  • Zuletzt bearbeitet 21.11.2024 08:03:04

Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passed` branches, multiple duplicate topics could be created if topic embedding is enabled. This issue is ...

  • EPSS 0.4%
  • Veröffentlicht 13.06.2023 22:15:09
  • Zuletzt bearbeitet 21.11.2024 08:06:51

Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passed` branches, an attacker could use the new topics dismissal endpoint to reveal the number of topics r...

  • EPSS 0.36%
  • Veröffentlicht 18.04.2023 22:15:08
  • Zuletzt bearbeitet 21.11.2024 08:00:22

Discourse is an open source platform for community discussion. Due to the improper sanitization of SVG files, an attacker can execute arbitrary JavaScript on the users’ browsers by uploading a crafted SVG file. This issue is patched in the latest sta...

  • EPSS 0.39%
  • Veröffentlicht 18.04.2023 22:15:08
  • Zuletzt bearbeitet 21.11.2024 08:00:29

Discourse is an open source platform for community discussion. In affected versions a user logged as an administrator can call arbitrary methods on the `SiteSetting` class, notably `#clear_cache!` and `#notify_changed!`, which when done on a multisit...

  • EPSS 0.31%
  • Veröffentlicht 18.04.2023 22:15:07
  • Zuletzt bearbeitet 21.11.2024 07:56:41

Discourse is an open source platform for community discussion. This vulnerability is not exploitable on the default install of Discourse. A custom feature must be enabled for it to work at all, and the attacker’s payload must pass the CSP to be execu...

  • EPSS 0.69%
  • Veröffentlicht 18.04.2023 21:15:09
  • Zuletzt bearbeitet 21.11.2024 07:55:04

Discourse is an open source platform for community discussion. In affected versions a maliciously crafted request from a Discourse administrator can lead to a long-running request and eventual timeout. This has the greatest potential impact in shared...