VYPR

Bitnami package

discourse

pkg:bitnami/discourse

Vulnerabilities (274)

  • CVE-2024-36122LowJul 3, 2024
    affected < 3.2.3fixed 3.2.3

    Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta4 on the `beta` and `tests-passed` branches, moderators using the review queue to review users may see a users email address even when the Allow moderators to view

  • CVE-2024-36113MedJul 3, 2024
    affected < 3.2.3fixed 3.2.3

    Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch, version 3.3.0.beta3 on the `beta` branch, and version 3.3.0.beta4-dev on the `tests-passed` branch, a rogue staff user could suspend other staff users preventing them from logging in t

  • CVE-2024-35234MedJul 3, 2024
    affected < 3.2.3fixed 3.2.3

    Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta3 on the `tests-passed` branch, an attacker can execute arbitrary JavaScript on users’ browsers by posting a specific URL containing maliciously crafted meta tags.

  • CVE-2024-35227HigJul 3, 2024
    affected < 3.2.3fixed 3.2.3

    Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta3 on the `tests-passed` branch, Oneboxing against a carefully crafted malicious URL can reduce the availability of a Discourse instance. The problem has been patch

  • CVE-2024-28242MedMar 15, 2024
    affected < 3.2.1fixed 3.2.1

    Discourse is an open source platform for community discussion. In affected versions an attacker can learn that secret categories exist when they have backgrounds set. The issue is patched in the latest stable, beta and tests-passed version of Discourse. Users are advised to upgra

  • CVE-2024-27100MedMar 15, 2024
    affected < 3.2.1fixed 3.2.1

    Discourse is an open source platform for community discussion. In affected versions the endpoints for suspending users, silencing users and exporting CSV files weren't enforcing limits on the sizes of the parameters that they accept. This could lead to excessive resource consumpt

  • CVE-2024-27085MedMar 15, 2024
    affected < 3.2.1fixed 3.2.1

    Discourse is an open source platform for community discussion. In affected versions users that are allowed to invite others can inject arbitrarily large data in parameters used in the invite route. The problem has been patched in the latest version of Discourse. Users are advised

  • CVE-2024-24827MedMar 15, 2024
    affected < 3.2.1fixed 3.2.1

    Discourse is an open source platform for community discussion. Without a rate limit on the POST /uploads endpoint, it makes it easier for an attacker to carry out a DoS attack on the server since creating an upload can be a resource intensive process. Do note that the impact vari

  • CVE-2024-24748MedMar 15, 2024
    affected < 3.2.1fixed 3.2.1

    Discourse is an open source platform for community discussion. In affected versions an attacker can learn that a secret subcategory exists under a public category which has no public subcategories. The issue is patched in the latest stable, beta and tests-passed version of Discou

  • CVE-2024-23834MedJan 30, 2024
    affected < 3.2.0fixed 3.2.0

    Discourse is an open-source discussion platform. Improperly sanitized user input could lead to an XSS vulnerability in some situations. This vulnerability only affects Discourse instances which have disabled the default Content Security Policy. The vulnerability is patched in 3.1

  • CVE-2024-21655MedJan 12, 2024
    affected < 3.1.4fixed 3.1.4

    Discourse is a platform for community discussion. For fields that are client editable, limits on sizes are not imposed. This allows a malicious actor to cause a Discourse instance to use excessive disk space and also often excessive bandwidth. The issue is patched 3.1.4 and 3.2.0

  • CVE-2023-49099LowJan 12, 2024
    affected < 3.1.4fixed 3.1.4

    Discourse is a platform for community discussion. Under very specific circumstances, secure upload URLs associated with posts can be accessed by guest users even when login is required. This vulnerability has been patched in 3.2.0.beta4 and 3.1.4.

  • CVE-2023-48297HigJan 12, 2024
    affected < 3.1.4fixed 3.1.4

    Discourse is a platform for community discussion. The message serializer uses the full list of expanded chat mentions (@all and @here) which can lead to a very long array of users. This issue was patched in versions 3.1.4 and beta 3.2.0.beta5.

  • CVE-2023-47121LowNov 10, 2023
    affected < 3.2.0fixed 3.2.0

    Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, the embedding feature is susceptible to server side request forgery. The issue is patched in version 3.1

  • CVE-2023-47120HigNov 10, 2023
    affected >= 3.1.0, < 3.1.3fixed 3.1.3

    Discourse is an open source platform for community discussion. In versions 3.1.0 through 3.1.2 of the `stable` branch and versions 3.1.0,beta6 through 3.2.0.beta2 of the `beta` and `tests-passed` branches, Redis memory can be depleted by crafting a site with an abnormally long fa

  • CVE-2023-47119MedNov 10, 2023
    affected < 3.2.0fixed 3.2.0

    Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, some links can inject arbitrary HTML tags when rendered through our Onebox engine. The issue is patched

  • CVE-2023-46130MedNov 10, 2023
    affected < 3.2.0fixed 3.2.0

    Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, some theme components allow users to add svgs with unlimited `height` attributes, and this can affect th

  • CVE-2023-45816LowNov 10, 2023
    affected < 3.2.0fixed 3.2.0

    Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, there is an edge case where a bookmark reminder is sent and an unread notification is generated, but the

  • CVE-2023-45806MedNov 10, 2023
    affected < 3.2.0fixed 3.2.0

    Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, if a user has been quoted and uses a `|` in their full name, they might be able to trigger a bug that ge

  • CVE-2023-45131HigOct 16, 2023
    affected <= 3.1.1

    Discourse is an open source platform for community discussion. New chat messages can be read by making an unauthenticated POST request to MessageBus. This issue is patched in the 3.1.1 stable and 3.2.0.beta2 versions of Discourse. Users are advised to upgrade. There are no known

Page 9 of 14