VYPR

Bitnami package

discourse

pkg:bitnami/discourse

Vulnerabilities (274)

  • CVE-2023-22740MedJan 27, 2023
    affected < 3.0.1fixed 3.0.1

    Discourse is an open source platform for community discussion. Versions prior to 3.1.0.beta1 (beta) (tests-passed) are vulnerable to Allocation of Resources Without Limits. Users can create chat drafts of an unlimited length, which can cause a denial of service by generating an

  • CVE-2023-22739MedJan 26, 2023
    affected < 3.0.1fixed 3.0.1

    Discourse is an open source platform for community discussion. Versions prior to 3.0.1 (stable), 3.1.0.beta2 (beta), and 3.1.0.beta2 (tests-passed) are subject to Allocation of Resources Without Limits or Throttling. As there is no limit on data contained in a draft, a malicious

  • CVE-2023-22468HigJan 26, 2023
    affected < 2.8.13fixed 2.8.13

    Discourse is an open source platform for community discussion. Versions prior to 2.8.13 (stable), 3.0.0.beta16 (beta) and 3.0.0beta16 (tests-passed), are vulnerable to cross-site Scripting. A maliciously crafted URL can be included in a post to carry out cross-site scripting att

  • CVE-2023-22455MedJan 5, 2023
    affected < 2.8.14fixed 2.8.14

    Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 3.0.0.beta16 on the `beta` and `tests-passed` branches, tag descriptions, which can be updated by moderators, can be used for cross-site scripting attacks. This vulnerabi

  • CVE-2023-22454HigJan 5, 2023
    affected < 2.8.14fixed 2.8.14

    Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 3.0.0.beta16 on the `beta` and `tests-passed` branches, pending post titles can be used for cross-site scripting attacks. Pending posts can be created by unprivileged use

  • CVE-2023-22453MedJan 5, 2023
    affected < 2.8.14fixed 2.8.14

    Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 3.0.0.beta16 on the `beta` and `tests-passed` branches, the number of times a user posted in an arbitrary topic is exposed to unauthorized users through the `/u/username.

  • CVE-2022-46177MedJan 5, 2023
    affected < 2.8.14fixed 2.8.14

    Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 3.0.0.beta16 on the `beta` and `tests-passed` branches, when a user requests for a password reset link email, then changes their primary email, the old reset email is sti

  • CVE-2022-23549MedJan 5, 2023
    affected < 2.8.14fixed 2.8.14

    Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 2.9.0.beta16 on the `beta` and `tests-passed` branches, users can create posts with raw body longer than the `max_length` site setting by including html comments that are

  • CVE-2022-23548MedJan 5, 2023
    affected < 2.8.14fixed 2.8.14

    Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 2.9.0.beta16 on the `beta` and `tests-passed` branches, parsing posts can be susceptible to regular expression denial of service (ReDoS) attacks. This issue is patched in

  • CVE-2022-23546MedJan 5, 2023
    affected < 2.9.0fixed 2.9.0

    In version 2.9.0.beta14 of Discourse, an open-source discussion platform, maliciously embedded urls can leak an admin's digest of recent topics, possibly exposing private information. A patch is available for version 2.9.0.beta15. There are no known workarounds for this issue.

  • CVE-2022-46168LowJan 5, 2023
    affected < 2.8.14fixed 2.8.14

    Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 2.9.0.beta15 on the `beta` and `tests-passed` branches, recipients of a group SMTP email could see the email addresses of all other users inside the group SMTP topic. Mos

  • CVE-2022-46159MedDec 2, 2022
    affected < 2.8.14fixed 2.8.14

    Discourse is an open-source discussion platform. In version 2.8.13 and prior on the `stable` branch and version 2.9.0.beta14 and prior on the `beta` and `tests-passed` branches, any authenticated user can create an unlisted topic. These topics, which are not readily available to

  • CVE-2022-46150MedNov 29, 2022
    affected < 2.8.13fixed 2.8.13

    Discourse is an open-source discussion platform. Prior to version 2.8.13 of the `stable` branch and version 2.9.0.beta14 of the `beta` and `tests-passed` branches, unauthorized users may learn of the existence of hidden tags and that they have been applied to topics that they hav

  • CVE-2022-46148HigNov 29, 2022
    affected < 2.8.11fixed 2.8.11

    Discourse is an open-source messaging platform. In versions 2.8.10 and prior on the `stable` branch and versions 2.9.0.beta11 and prior on the `beta` and `tests-passed` branches, users composing malicious messages and navigating to drafts page could self-XSS. This vulnerability c

  • CVE-2022-41944LowNov 28, 2022
    affected < 2.8.12fixed 2.8.12

    Discourse is an open-source discussion platform. In stable versions prior to 2.8.12 and beta or tests-passed versions prior to 2.9.0.beta.13, under certain conditions, a user can see notifications for topics they no longer have access to. If there is sensitive information in the

  • CVE-2022-41921LowNov 28, 2022
    affected < 2.9.0fixed 2.9.0

    Discourse is an open-source discussion platform. Prior to version 2.9.0.beta13, users can post chat messages of an unlimited length, which can cause a denial of service for other users when posting huge amounts of text. Users should upgrade to version 2.9.0.beta13, where a limit

  • CVE-2022-39385MedNov 14, 2022
    affected < 2.8.10fixed 2.8.10

    Discourse is the an open source discussion platform. In some rare cases users redeeming an invitation can be added as a participant to several private message topics that they should not be added to. They are not notified of this, it happens transparently in the background. This

  • CVE-2022-39378MedNov 2, 2022
    affected < 2.8.9fixed 2.8.9

    Discourse is a platform for community discussion. Under certain conditions, a user badge may have been awarded based on a user's activity in a topic with restricted access. Before this vulnerability was disclosed, the topic title of the topic associated with the user badge may be

  • CVE-2022-39356HigNov 2, 2022
    affected < 2.8.10fixed 2.8.10

    Discourse is a platform for community discussion. Users who receive an invitation link that is not scoped to a single email address can enter any non-admin user's email and gain access to their account when accepting the invitation. All users should upgrade to the latest version.

  • CVE-2022-39241HigNov 2, 2022
    affected < 2.8.10fixed 2.8.10

    Discourse is a platform for community discussion. A malicious admin could use this vulnerability to perform port enumeration on the local host or other hosts on the internal network, as well as against hosts on the Internet. Latest `stable`, `beta`, and `test-passed` versions are