CVE-2024-38360
Last modified
CVE-2024-38360 is a medium-severity vulnerability rated 4.9/10 on the CVSS scale. Discourse is an open source platform for community discussion. In affected versions by creating replacement words with an almost unlimited number of characters, a moderator can reduce the availability of a Discourse instance. EPSS estimates a 0.47% chance of exploitation in the next 30 days.
Description
Discourse is an open source platform for community discussion. In affected versions by creating replacement words with an almost unlimited number of characters, a moderator can reduce the availability of a Discourse instance. This issue has been addressed in stable version 3.2.3 and in current betas. Users are advised to upgrade. Users unable to upgrade may manually remove the long watched words either via SQL or Rails console.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Discourse | Discourse | < 3.3.0 | — |
| Discourse | Discourse | < 3.3.2 | — |
| Discourse | Discourse | 3.3.0 | Beta1 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-38360?
How severe is CVE-2024-38360?
How do I fix CVE-2024-38360?
Are you affected by CVE-2024-38360?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
