CVE-2023-28112
- EPSS 0.58%
- Veröffentlicht 17.03.2023 19:15:11
- Zuletzt bearbeitet 21.11.2024 07:54:25
Discourse is an open-source discussion platform. Prior to version 3.1.0.beta3 of the `beta` and `tests-passed` branches, some user provided URLs were being passed to FastImage without SSRF protection. Insufficient protections could enable attackers t...
CVE-2023-25172
- EPSS 0.45%
- Veröffentlicht 17.03.2023 17:15:11
- Zuletzt bearbeitet 21.11.2024 07:49:14
Discourse is an open-source discussion platform. Prior to version 3.0.1 of the `stable` branch and version 3.1.0.beta2 of the `beta` and `tests-passed` branches, a maliciously crafted URL can be included in a user's full name field to to carry out cr...
CVE-2023-28107
- EPSS 0.65%
- Veröffentlicht 17.03.2023 17:15:11
- Zuletzt bearbeitet 21.11.2024 07:54:25
Discourse is an open-source discussion platform. Prior to version 3.0.2 of the `stable` branch and version 3.1.0.beta3 of the `beta` and `tests-passed` branches, a user logged as an administrator can request backups multiple times, which will eat up ...
CVE-2023-28111
- EPSS 0.56%
- Veröffentlicht 17.03.2023 17:15:11
- Zuletzt bearbeitet 21.11.2024 07:54:25
Discourse is an open-source discussion platform. Prior to version 3.1.0.beta3 of the `beta` and `tests-passed` branches, attackers are able to bypass Discourse's server-side request forgery (SSRF) protection for private IPv4 addresses by using a IPv4...
CVE-2023-23622
- EPSS 0.53%
- Veröffentlicht 17.03.2023 15:15:12
- Zuletzt bearbeitet 21.11.2024 07:46:33
Discourse is an open-source discussion platform. Prior to version 3.0.1 of the `stable` branch and version 3.1.0.beta2 of the `beta` and `tests-passed` branches, the count of topics displayed for a tag is a count of all regular topics regardless of w...
CVE-2023-26040
- EPSS 0.35%
- Veröffentlicht 17.03.2023 15:15:12
- Zuletzt bearbeitet 21.11.2024 07:50:38
Discourse is an open-source discussion platform. Between versions 3.1.0.beta2 and 3.1.0.beta3 of the `tests-passed` branch, editing or responding to a chat message containing malicious content could lead to a cross-site scripting attack. This issue i...
CVE-2023-23935
- EPSS 0.5%
- Veröffentlicht 16.03.2023 21:15:13
- Zuletzt bearbeitet 21.11.2024 07:47:08
Discourse is an open-source messaging platform. In versions 3.0.1 and prior on the `stable` branch and versions 3.1.0.beta2 and prior on the `beta` and `tests-passed` branches, the count of personal messages displayed for a tag is a count of all pers...
CVE-2023-25819
- EPSS 0.5%
- Veröffentlicht 04.03.2023 01:15:10
- Zuletzt bearbeitet 21.11.2024 07:50:15
Discourse is an open source platform for community discussion. Tags that are normally private are showing in metadata. This affects any site running the `tests-passed` or `beta` branches >= 3.1.0.beta2. The issue is patched in the latest `beta` and `...
CVE-2023-25167
- EPSS 0.57%
- Veröffentlicht 08.02.2023 20:15:25
- Zuletzt bearbeitet 21.11.2024 07:49:14
Discourse is an open source discussion platform. In affected versions a malicious user can cause a regular expression denial of service using a carefully crafted git URL. This issue is patched in the latest stable, beta and tests-passed versions of D...
CVE-2023-23615
- EPSS 0.45%
- Veröffentlicht 03.02.2023 22:15:12
- Zuletzt bearbeitet 21.11.2024 07:46:32
Discourse is an open source discussion platform. The embeddable comments can be exploited to create new topics as any user but without any clear title or content. This issue is patched in the latest stable, beta and tests-passed versions of Discourse...