Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-43850

Опубликовано: 04 янв. 2022
Источник: nvd
CVSS3: 6.8
CVSS3: 6.8
CVSS2: 4
EPSS Низкий

Описание

Discourse is an open source platform for community discussion. In affected versions admins users can trigger a Denial of Service attack via the /message-bus/_diagnostics path. The impact of this vulnerability is greater on multisite Discourse instances (where multiple forums are served from a single application server) where any admin user on any of the forums are able to visit the /message-bus/_diagnostics path. The problem has been patched. Please upgrade to 2.8.0.beta10 or 2.7.12. No workarounds for this issue exist.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*
Версия до 2.7.12 (исключая)
cpe:2.3:a:discourse:discourse:2.8.0:beta1:*:*:*:*:*:*
cpe:2.3:a:discourse:discourse:2.8.0:beta2:*:*:*:*:*:*
cpe:2.3:a:discourse:discourse:2.8.0:beta3:*:*:*:*:*:*
cpe:2.3:a:discourse:discourse:2.8.0:beta4:*:*:*:*:*:*
cpe:2.3:a:discourse:discourse:2.8.0:beta5:*:*:*:*:*:*
cpe:2.3:a:discourse:discourse:2.8.0:beta6:*:*:*:*:*:*
cpe:2.3:a:discourse:discourse:2.8.0:beta7:*:*:*:*:*:*
cpe:2.3:a:discourse:discourse:2.8.0:beta8:*:*:*:*:*:*
cpe:2.3:a:discourse:discourse:2.8.0:beta9:*:*:*:*:*:*

EPSS

Процентиль: 53%
0.00297
Низкий

6.8 Medium

CVSS3

6.8 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-20
NVD-CWE-noinfo

EPSS

Процентиль: 53%
0.00297
Низкий

6.8 Medium

CVSS3

6.8 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-20
NVD-CWE-noinfo