PT-2023-3566 · Discourse · Discourse

·

CVE-2023-36466

·

Published

2023-06-21

·

Updated

2024-03-06

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions Discourse versions prior to the latest stable, beta and tests-passed version
Description The issue is related to insufficient input validation when processing topic titles, allowing a remote attacker to impact the integrity and availability of protected information. The vulnerability enables a user to bypass topic title validations, such as title length, number of emojis in the title, and blank topic titles, when editing a topic.
Recommendations For versions prior to the latest stable, beta and tests-passed version, update to the latest stable, beta or tests-passed version to resolve the issue. As a temporary workaround, consider restricting the ability to edit topic titles until the update is applied.

Exploit

Fix

DoS

Improper Authentication

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-03787
BIT-DISCOURSE-2023-36466
CVE-2023-36466
GHSA-4HJH-WG43-P932

Affected Products

Discourse