Discourse is an open source platform for community discussion. A user can create a post with many replies, and then attempt to fetch them all at once. This can potentially reduce the availability of a Discourse instance. This problem has been patched in the latest version of Discourse. All users area are advised to upgrade. There are no known workarounds for this vulnerability.
Metrics
Affected Vendors & Products
References
History
Sat, 19 Oct 2024 01:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:discourse:discourse:*:*:*:*:beta:*:*:* cpe:2.3:a:discourse:discourse:*:*:*:*:stable:*:*:* cpe:2.3:a:discourse:discourse:3.4.0:-:*:*:beta:*:*:* |
Tue, 08 Oct 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Discourse
Discourse discourse |
|
CPEs | cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:* | |
Vendors & Products |
Discourse
Discourse discourse |
|
Metrics |
ssvc
|
Mon, 07 Oct 2024 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Discourse is an open source platform for community discussion. A user can create a post with many replies, and then attempt to fetch them all at once. This can potentially reduce the availability of a Discourse instance. This problem has been patched in the latest version of Discourse. All users area are advised to upgrade. There are no known workarounds for this vulnerability. | |
Title | Denial of service by the absence of restrictions on replies to posts in Discourse | |
Weaknesses | CWE-400 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-10-07T20:24:32.007Z
Updated: 2024-10-08T18:11:24.827Z
Reserved: 2024-08-16T14:20:37.323Z
Link: CVE-2024-43789
Vulnrichment
Updated: 2024-10-08T18:11:18.473Z
NVD
Status : Analyzed
Published: 2024-10-07T21:15:16.710
Modified: 2024-10-19T01:13:38.170
Link: CVE-2024-43789
Redhat
No data.