VYPR
Medium severity4.9NVD Advisory· Published Jul 30, 2024· Updated Jun 17, 2026

CVE-2024-37299

CVE-2024-37299

Description

Discourse is an open source discussion platform. Prior to 3.2.5 and 3.3.0.beta5, crafting requests to submit very long tag group names can reduce the availability of a Discourse instance. This vulnerability is fixed in 3.2.5 and 3.3.0.beta5.

Affected products

8
  • cpe:2.3:a:discourse:discourse:*:*:*:*:stable:*:*:*+ 6 more
    • cpe:2.3:a:discourse:discourse:*:*:*:*:stable:*:*:*range: <3.2.5
    • cpe:2.3:a:discourse:discourse:3.3.0:beta1:*:*:beta:*:*:*
    • cpe:2.3:a:discourse:discourse:3.3.0:beta2:*:*:beta:*:*:*
    • cpe:2.3:a:discourse:discourse:3.3.0:beta3:*:*:beta:*:*:*
    • cpe:2.3:a:discourse:discourse:3.3.0:beta4:*:*:beta:*:*:*
    • (no CPE)range: <3.2.5, <3.3.0.beta5
    • (no CPE)range: < 3.2.5
  • osv-coords
    Range: < 3.2.5

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.