discourse-calendar is a discourse plugin which adds the ability to create a dynamic calendar in the first post of a topic. The limit on region value length is too generous. This allows a malicious actor to cause a Discourse instance to use excessive bandwidth and disk space. This issue has been patched in main the main branch. There are no workarounds for this vulnerability. Please upgrade as soon as possible.
Metrics
Affected Vendors & Products
References
History
Thu, 05 Sep 2024 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Discourse
Discourse discourse Calendar |
|
Weaknesses | CWE-770 | |
CPEs | cpe:2.3:a:discourse:discourse_calendar:*:*:*:*:*:discourse:*:* | |
Vendors & Products |
Discourse
Discourse discourse Calendar |
Fri, 30 Aug 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 30 Aug 2024 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | discourse-calendar is a discourse plugin which adds the ability to create a dynamic calendar in the first post of a topic. The limit on region value length is too generous. This allows a malicious actor to cause a Discourse instance to use excessive bandwidth and disk space. This issue has been patched in main the main branch. There are no workarounds for this vulnerability. Please upgrade as soon as possible. | |
Title | Insufficient control of region value length in discourse-calendar | |
Weaknesses | CWE-400 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-08-30T17:18:40.593Z
Updated: 2024-08-30T18:00:51.765Z
Reserved: 2023-12-29T16:10:20.367Z
Link: CVE-2024-21658
Vulnrichment
Updated: 2024-08-30T18:00:43.034Z
NVD
Status : Analyzed
Published: 2024-08-30T18:15:06.717
Modified: 2024-09-05T14:39:07.033
Link: CVE-2024-21658
Redhat
No data.