Medium severity4.2NVD Advisory· Published Apr 18, 2023· Updated Jun 17, 2026
CVE-2023-30606
CVE-2023-30606
Description
Discourse is an open source platform for community discussion. In affected versions a user logged as an administrator can call arbitrary methods on the SiteSetting class, notably #clear_cache! and #notify_changed!, which when done on a multisite instance, can affect the entire cluster resulting in a denial of service. Users not running in multisite environments are not affected. This issue is patched in the latest stable, beta and tests-passed versions of Discourse. Users are advised to upgrade. There are no known workarounds for this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7stable: < 3.0.2+ 5 more
- (no CPE)range: stable: < 3.0.2
- cpe:2.3:a:discourse:discourse:*:*:*:*:stable:*:*:*range: <=3.0.1
- cpe:2.3:a:discourse:discourse:*:*:*:*:beta:*:*:*range: <3.1.0
- cpe:2.3:a:discourse:discourse:3.1.0:beta1:*:*:beta:*:*:*
- cpe:2.3:a:discourse:discourse:3.1.0:beta2:*:*:beta:*:*:*
- (no CPE)
Patches
Vulnerability mechanics
References
1- github.com/discourse/discourse/security/advisories/GHSA-jj93-w3mv-3jvvnvdThird Party Advisory
News mentions
0No linked articles in our index yet.