Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-46130

Опубликовано: 10 нояб. 2023
Источник: nvd
CVSS3: 4.3
CVSS3: 5.4
EPSS Низкий

Описание

Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the stable branch and version 3.2.0.beta3 of the beta and tests-passed branches, some theme components allow users to add svgs with unlimited height attributes, and this can affect the availability of subsequent replies in a topic. Most Discourse instances are unaffected, only instances with the svgbob or the mermaid theme component are within scope. The issue is patched in version 3.1.3 of the stable branch and version 3.2.0.beta3 of the beta and tests-passed branches. As a workaround, disable or remove the relevant theme components.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:discourse:discourse:*:*:*:*:stable:*:*:*
Версия до 3.1.3 (исключая)
cpe:2.3:a:discourse:discourse:*:*:*:*:beta:*:*:*
Версия до 3.2.0 (исключая)
cpe:2.3:a:discourse:discourse:3.2.0:beta1:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:3.2.0:beta2:*:*:beta:*:*:*

EPSS

Процентиль: 41%
0.00194
Низкий

4.3 Medium

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-770

EPSS

Процентиль: 41%
0.00194
Низкий

4.3 Medium

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-770