VYPR
Unrated severityNVD Advisory· Published Oct 7, 2024· Updated Oct 8, 2024

Denial of service by the absence of restrictions on replies to posts in Discourse

CVE-2024-43789

Description

Discourse is an open source platform for community discussion. A user can create a post with many replies, and then attempt to fetch them all at once. This can potentially reduce the availability of a Discourse instance. This problem has been patched in the latest version of Discourse. All users area are advised to upgrade. There are no known workarounds for this vulnerability.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.