CVE-2023-46130
- EPSS 0.7%
- Veröffentlicht 10.11.2023 15:15:08
- Zuletzt bearbeitet 21.11.2024 08:27:56
Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, some theme components allow users to add svgs with unlimited `height` attr...
CVE-2023-43659
- EPSS 0.42%
- Veröffentlicht 16.10.2023 22:15:12
- Zuletzt bearbeitet 21.11.2024 08:24:33
Discourse is an open source platform for community discussion. Improper escaping of user input allowed for Cross-site Scripting attacks via the digest email preview UI. This issue only affects sites with CSP disabled. This issue has been patched in t...
CVE-2023-43814
- EPSS 0.31%
- Veröffentlicht 16.10.2023 22:15:12
- Zuletzt bearbeitet 21.11.2024 08:24:49
Discourse is an open source platform for community discussion. Attackers with details specific to a poll in a topic can use the `/polls/grouped_poll_results` endpoint to view the content of options in the poll and the number of votes for groups of po...
CVE-2023-44388
- EPSS 0.53%
- Veröffentlicht 16.10.2023 22:15:12
- Zuletzt bearbeitet 21.11.2024 08:25:47
Discourse is an open source platform for community discussion. A malicious request can cause production log files to quickly fill up and thus result in the server running out of disk space. This problem has been patched in the 3.1.1 stable and 3.2.0....
CVE-2023-44391
- EPSS 0.41%
- Veröffentlicht 16.10.2023 22:15:12
- Zuletzt bearbeitet 21.11.2024 08:25:48
Discourse is an open source platform for community discussion. User summaries are accessible for anonymous users even when `hide_user_profiles_from_public` is enabled. This problem has been patched in the 3.1.1 stable and 3.2.0.beta2 version of Disco...
CVE-2023-45131
- EPSS 1.81%
- Veröffentlicht 16.10.2023 22:15:12
- Zuletzt bearbeitet 21.11.2024 08:26:24
Discourse is an open source platform for community discussion. New chat messages can be read by making an unauthenticated POST request to MessageBus. This issue is patched in the 3.1.1 stable and 3.2.0.beta2 versions of Discourse. Users are advised t...
CVE-2023-45147
- EPSS 0.27%
- Veröffentlicht 16.10.2023 21:15:11
- Zuletzt bearbeitet 21.11.2024 08:26:26
Discourse is an open source community platform. In affected versions any user can create a topic and add arbitrary custom fields to a topic. The severity of this vulnerability depends on what plugins are installed and how the plugins uses topic custo...
CVE-2023-40588
- EPSS 0.51%
- Veröffentlicht 15.09.2023 20:15:10
- Zuletzt bearbeitet 21.11.2024 08:19:46
Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 of the `beta` and `tests-passed` branches, a malicious user could add a 2FA or security key with a carefully crafted name to their ...
CVE-2023-41042
- EPSS 0.51%
- Veröffentlicht 15.09.2023 20:15:10
- Zuletzt bearbeitet 21.11.2024 08:20:26
Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 of the `beta` and `tests-passed` branches, importing a remote theme loads their assets into memory without enforcing limits for fil...
CVE-2023-41043
- EPSS 0.51%
- Veröffentlicht 15.09.2023 20:15:10
- Zuletzt bearbeitet 21.11.2024 08:20:26
Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 of the `beta` and `tests-passed` branches, a malicious admin could create extremely large icons sprites, which would then be cached...