PT-2022-26151 · Discourse · Discourse

·

CVE-2022-41921

·

Published

2022-11-28

·

Updated

2024-03-06

CVSS v3.1

3.5

Low

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Discourse versions prior to 2.9.0.beta13
Description Discourse is an open-source discussion platform. The issue allows users to post chat messages of an unlimited length, which can cause a denial of service for other users when huge amounts of text are posted.
Recommendations For versions prior to 2.9.0.beta13, users should upgrade to version 2.9.0.beta13, where a limit on chat message length has been introduced to prevent the denial of service issue.

Exploit

Fix

DoS

Allocation of Resources Without Limits

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2022-41921
CVE-2022-41921
GHSA-MFH7-6CV6-QCCC

Affected Products

Discourse