Описание
Discourse is an open source discussion platform. In affected versions a request to create or update custom sidebar section can cause a denial of service. This issue has been patched in commit 52b003d915. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Ссылки
- Patch
- Vendor Advisory
- Patch
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:discourse:discourse:3.1.0:beta5:*:*:beta:*:*:*
EPSS
Процентиль: 52%
0.00292
Низкий
6.5 Medium
CVSS3
7.5 High
CVSS3
Дефекты
CWE-400
NVD-CWE-noinfo
EPSS
Процентиль: 52%
0.00292
Низкий
6.5 Medium
CVSS3
7.5 High
CVSS3
Дефекты
CWE-400
NVD-CWE-noinfo