Discourse

Discourse

252 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.57%
  • Veröffentlicht 05.01.2023 20:15:18
  • Zuletzt bearbeitet 21.11.2024 07:44:50

Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 3.0.0.beta16 on the `beta` and `tests-passed` branches, pending post titles can be used for cross-site scripting attacks. Pending posts can ...

  • EPSS 0.28%
  • Veröffentlicht 05.01.2023 19:15:09
  • Zuletzt bearbeitet 21.11.2024 06:48:47

In version 2.9.0.beta14 of Discourse, an open-source discussion platform, maliciously embedded urls can leak an admin's digest of recent topics, possibly exposing private information. A patch is available for version 2.9.0.beta15. There are no known ...

  • EPSS 0.74%
  • Veröffentlicht 05.01.2023 19:15:09
  • Zuletzt bearbeitet 21.11.2024 06:48:47

Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 2.9.0.beta16 on the `beta` and `tests-passed` branches, parsing posts can be susceptible to regular expression denial of service (ReDoS) att...

  • EPSS 0.58%
  • Veröffentlicht 05.01.2023 19:15:09
  • Zuletzt bearbeitet 21.11.2024 06:48:47

Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 2.9.0.beta16 on the `beta` and `tests-passed` branches, users can create posts with raw body longer than the `max_length` site setting by in...

  • EPSS 0.52%
  • Veröffentlicht 05.01.2023 18:15:08
  • Zuletzt bearbeitet 21.11.2024 07:30:14

Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 2.9.0.beta15 on the `beta` and `tests-passed` branches, recipients of a group SMTP email could see the email addresses of all other users in...

  • EPSS 0.61%
  • Veröffentlicht 02.12.2022 15:15:10
  • Zuletzt bearbeitet 21.11.2024 07:30:13

Discourse is an open-source discussion platform. In version 2.8.13 and prior on the `stable` branch and version 2.9.0.beta14 and prior on the `beta` and `tests-passed` branches, any authenticated user can create an unlisted topic. These topics, which...

  • EPSS 0.52%
  • Veröffentlicht 29.11.2022 18:15:10
  • Zuletzt bearbeitet 21.11.2024 07:30:12

Discourse is an open-source discussion platform. Prior to version 2.8.13 of the `stable` branch and version 2.9.0.beta14 of the `beta` and `tests-passed` branches, unauthorized users may learn of the existence of hidden tags and that they have been a...

  • EPSS 0.45%
  • Veröffentlicht 29.11.2022 17:15:11
  • Zuletzt bearbeitet 21.11.2024 07:30:12

Discourse is an open-source messaging platform. In versions 2.8.10 and prior on the `stable` branch and versions 2.9.0.beta11 and prior on the `beta` and `tests-passed` branches, users composing malicious messages and navigating to drafts page could ...

  • EPSS 0.5%
  • Veröffentlicht 28.11.2022 15:15:10
  • Zuletzt bearbeitet 21.11.2024 07:24:04

Discourse is an open-source discussion platform. Prior to version 2.9.0.beta13, users can post chat messages of an unlimited length, which can cause a denial of service for other users when posting huge amounts of text. Users should upgrade to versio...

  • EPSS 0.45%
  • Veröffentlicht 28.11.2022 15:15:10
  • Zuletzt bearbeitet 21.11.2024 07:24:07

Discourse is an open-source discussion platform. In stable versions prior to 2.8.12 and beta or tests-passed versions prior to 2.9.0.beta.13, under certain conditions, a user can see notifications for topics they no longer have access to. If there is...