CVE-2023-23616
- EPSS 0.68%
- Veröffentlicht 28.01.2023 00:15:09
- Zuletzt bearbeitet 21.11.2024 07:46:32
Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and 3.1.0.beta2 on the `beta` and `tests-passed` branches, when submitting a membership request, there is no character limit for the reason provided with t...
CVE-2023-23620
- EPSS 0.67%
- Veröffentlicht 28.01.2023 00:15:09
- Zuletzt bearbeitet 21.11.2024 07:46:32
Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and 3.1.0.beta2 on the `beta` and `tests-passed` branches, the contents of latest/top routes for restricted tags can be accessed by unauthorized users. Thi...
CVE-2023-23621
- EPSS 0.87%
- Veröffentlicht 28.01.2023 00:15:09
- Zuletzt bearbeitet 21.11.2024 07:46:33
Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and version 3.1.0.beta2 on the `beta` and `tests-passed` branches, a malicious user can cause a regular expression denial of service using a carefully craf...
CVE-2023-23624
- EPSS 0.59%
- Veröffentlicht 28.01.2023 00:15:09
- Zuletzt bearbeitet 21.11.2024 07:46:33
Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and version 3.1.0.beta2 on the `beta` and `tests-passed` branches, someone can use the `exclude_tag param` to filter out topics and deduce which ones were ...
CVE-2023-22740
- EPSS 0.68%
- Veröffentlicht 27.01.2023 01:15:08
- Zuletzt bearbeitet 21.11.2024 07:45:19
Discourse is an open source platform for community discussion. Versions prior to 3.1.0.beta1 (beta) (tests-passed) are vulnerable to Allocation of Resources Without Limits. Users can create chat drafts of an unlimited length, which can cause a denia...
CVE-2023-22739
- EPSS 0.87%
- Veröffentlicht 26.01.2023 21:18:13
- Zuletzt bearbeitet 21.11.2024 07:45:19
Discourse is an open source platform for community discussion. Versions prior to 3.0.1 (stable), 3.1.0.beta2 (beta), and 3.1.0.beta2 (tests-passed) are subject to Allocation of Resources Without Limits or Throttling. As there is no limit on data cont...
CVE-2023-22468
- EPSS 0.5%
- Veröffentlicht 26.01.2023 21:18:12
- Zuletzt bearbeitet 21.11.2024 07:44:51
Discourse is an open source platform for community discussion. Versions prior to 2.8.13 (stable), 3.0.0.beta16 (beta) and 3.0.0beta16 (tests-passed), are vulnerable to cross-site Scripting. A maliciously crafted URL can be included in a post to carry...
CVE-2023-22455
- EPSS 0.48%
- Veröffentlicht 05.01.2023 21:15:09
- Zuletzt bearbeitet 21.11.2024 07:44:50
Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 3.0.0.beta16 on the `beta` and `tests-passed` branches, tag descriptions, which can be updated by moderators, can be used for cross-site scr...
CVE-2022-46177
- EPSS 0.68%
- Veröffentlicht 05.01.2023 20:15:18
- Zuletzt bearbeitet 21.11.2024 07:30:16
Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 3.0.0.beta16 on the `beta` and `tests-passed` branches, when a user requests for a password reset link email, then changes their primary ema...
CVE-2023-22453
- EPSS 0.58%
- Veröffentlicht 05.01.2023 20:15:18
- Zuletzt bearbeitet 21.11.2024 07:44:50
Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 3.0.0.beta16 on the `beta` and `tests-passed` branches, the number of times a user posted in an arbitrary topic is exposed to unauthorized u...