Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-21658

Опубликовано: 30 авг. 2024
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

discourse-calendar is a discourse plugin which adds the ability to create a dynamic calendar in the first post of a topic. The limit on region value length is too generous. This allows a malicious actor to cause a Discourse instance to use excessive bandwidth and disk space. This issue has been patched in main the main branch. There are no workarounds for this vulnerability. Please upgrade as soon as possible.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:discourse:discourse_calendar:*:*:*:*:*:discourse:*:*
Версия до 2024-08-28 (исключая)

EPSS

Процентиль: 44%
0.00212
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-400
CWE-770

EPSS

Процентиль: 44%
0.00212
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-400
CWE-770
Уязвимость CVE-2024-21658