VYPR
Medium severity4.2NVD Advisory· Published Apr 18, 2023· Updated Jun 17, 2026

CVE-2023-30606

CVE-2023-30606

Description

Discourse is an open source platform for community discussion. In affected versions a user logged as an administrator can call arbitrary methods on the SiteSetting class, notably #clear_cache! and #notify_changed!, which when done on a multisite instance, can affect the entire cluster resulting in a denial of service. Users not running in multisite environments are not affected. This issue is patched in the latest stable, beta and tests-passed versions of Discourse. Users are advised to upgrade. There are no known workarounds for this vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

7
  • osv-coords
    Range: < 3.1.0
  • stable: < 3.0.2+ 5 more
    • (no CPE)range: stable: < 3.0.2
    • cpe:2.3:a:discourse:discourse:*:*:*:*:stable:*:*:*range: <=3.0.1
    • cpe:2.3:a:discourse:discourse:*:*:*:*:beta:*:*:*range: <3.1.0
    • cpe:2.3:a:discourse:discourse:3.1.0:beta1:*:*:beta:*:*:*
    • cpe:2.3:a:discourse:discourse:3.1.0:beta2:*:*:beta:*:*:*
    • (no CPE)

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.