Discourse is an open source platform for community discussion. In affected versions an attacker can poison the cache for anonymous (i.e. not logged in) users, such that the users are shown the crawler view of the site instead of the HTML page. This can lead to a partial denial-of-service. This issue is patched in the latest stable, beta and tests-passed versions of Discourse. There are no known workarounds for this issue.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2022-04-14T21:15:14
Updated: 2024-08-03T04:20:50.534Z
Reserved: 2022-02-10T00:00:00
Link: CVE-2022-24824
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-04-14T22:15:07.827
Modified: 2024-11-21T06:51:10.793
Link: CVE-2022-24824
Redhat
No data.