VYPR

Bitnami package

discourse

pkg:bitnami/discourse

Vulnerabilities (274)

  • CVE-2023-44391MedOct 16, 2023
    affected <= 3.1.1

    Discourse is an open source platform for community discussion. User summaries are accessible for anonymous users even when `hide_user_profiles_from_public` is enabled. This problem has been patched in the 3.1.1 stable and 3.2.0.beta2 version of Discourse. Users are advised to upg

  • CVE-2023-44388HigOct 16, 2023
    affected <= 3.1.1

    Discourse is an open source platform for community discussion. A malicious request can cause production log files to quickly fill up and thus result in the server running out of disk space. This problem has been patched in the 3.1.1 stable and 3.2.0.beta2 versions of Discourse. I

  • CVE-2023-43814LowOct 16, 2023
    affected <= 3.1.1

    Discourse is an open source platform for community discussion. Attackers with details specific to a poll in a topic can use the `/polls/grouped_poll_results` endpoint to view the content of options in the poll and the number of votes for groups of poll participants. This impacts

  • CVE-2023-43659HigOct 16, 2023
    affected <= 3.1.1

    Discourse is an open source platform for community discussion. Improper escaping of user input allowed for Cross-site Scripting attacks via the digest email preview UI. This issue only affects sites with CSP disabled. This issue has been patched in the 3.1.1 stable release as wel

  • CVE-2023-45147MedOct 16, 2023
    affected <= 3.1.1

    Discourse is an open source community platform. In affected versions any user can create a topic and add arbitrary custom fields to a topic. The severity of this vulnerability depends on what plugins are installed and how the plugins uses topic custom fields. For a default Discou

  • CVE-2023-41043MedSep 15, 2023
    affected < 3.1.1fixed 3.1.1

    Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 of the `beta` and `tests-passed` branches, a malicious admin could create extremely large icons sprites, which would then be cached in each server process. This

  • CVE-2023-41042MedSep 15, 2023
    affected < 3.1.1fixed 3.1.1

    Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 of the `beta` and `tests-passed` branches, importing a remote theme loads their assets into memory without enforcing limits for file size or number of files. The

  • CVE-2023-40588MedSep 15, 2023
    affected < 3.1.1fixed 3.1.1

    Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 of the `beta` and `tests-passed` branches, a malicious user could add a 2FA or security key with a carefully crafted name to their account and cause a denial of

  • CVE-2023-38706MedSep 15, 2023
    affected < 3.1.1fixed 3.1.1

    Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 of the `beta` and `tests-passed` branches, a malicious user can create an unlimited number of drafts with very long draft keys which may end up exhausting the re

  • CVE-2023-38685MedJul 28, 2023
    affected < 3.0.6fixed 3.0.6

    Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, information about restricted-visibility topic tags could be obtained by unauthorized users. The issue is patched in ve

  • CVE-2023-38684MedJul 28, 2023
    affected < 3.0.6fixed 3.0.6

    Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, in multiple controller actions, Discourse accepts limit params but does not impose any upper bound on the values being

  • CVE-2023-38498MedJul 28, 2023
    affected < 3.0.6fixed 3.0.6

    Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, a malicious user can prevent the defer queue from proceeding promptly on sites hosted in the same multisite installati

  • CVE-2023-37906MedJul 28, 2023
    affected < 3.0.6fixed 3.0.6

    Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, a malicious user can edit a post in a topic and cause a DoS with a carefully crafted edit reason. The issue is patched

  • CVE-2023-37904LowJul 28, 2023
    affected < 3.0.6fixed 3.0.6

    Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, more users than permitted could be created from invite links. The issue is patched in version 3.0.6 of the `stable` br

  • CVE-2023-37467MedJul 28, 2023
    affected >= 1.1.0-beta1, <= 1.1.0-beta1

    Discourse is an open source discussion platform. Prior to version 3.1.0.beta7 of the `beta` and `tests-passed` branches, a CSP (Content Security Policy) nonce reuse vulnerability was discovered could allow cross-site scripting (XSS) attacks to bypass CSP protection for anonymous

  • CVE-2023-36818MedJul 14, 2023
    affected >= 3.1.0-beta5, <= 3.1.0-beta5

    Discourse is an open source discussion platform. In affected versions a request to create or update custom sidebar section can cause a denial of service. This issue has been patched in commit `52b003d915`. Users are advised to upgrade. There are no known workarounds for this vuln

  • CVE-2023-36466LowJul 14, 2023
    affected < 3.0.5fixed 3.0.5

    Discourse is an open source discussion platform. When editing a topic, there is a vulnerability that enables a user to bypass the topic title validations for things like title length, number of emojis in title and blank topic titles. The issue is patched in the latest stable, bet

  • CVE-2023-36473MedJul 13, 2023
    affected < 3.0.5fixed 3.0.5

    Discourse is an open source discussion platform. A CSP (Content Security Policy) nonce reuse vulnerability could allow XSS attacks to bypass CSP protection. There are no known XSS vectors at the moment, but should one be discovered, this vulnerability would allow the XSS attack t

  • CVE-2023-34250MedJun 13, 2023
    affected < 3.0.4fixed 3.0.4

    Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passed` branches, an attacker could use the new topics dismissal endpoint to reveal the number of topics recently created (but not the a

  • CVE-2023-32301LowJun 13, 2023
    affected < 3.0.4fixed 3.0.4

    Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passed` branches, multiple duplicate topics could be created if topic embedding is enabled. This issue is patched in version 3.0.4 of th

Page 10 of 14