Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-38360

Опубликовано: 15 июл. 2024
Источник: nvd
CVSS3: 4.9
EPSS Низкий

Описание

Discourse is an open source platform for community discussion. In affected versions by creating replacement words with an almost unlimited number of characters, a moderator can reduce the availability of a Discourse instance. This issue has been addressed in stable version 3.2.3 and in current betas. Users are advised to upgrade. Users unable to upgrade may manually remove the long watched words either via SQL or Rails console.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:discourse:discourse:*:*:*:*:beta:*:*:*
Версия до 3.3.0 (исключая)
cpe:2.3:a:discourse:discourse:*:*:*:*:stable:*:*:*
Версия до 3.3.2 (исключая)
cpe:2.3:a:discourse:discourse:3.3.0:beta1:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:3.3.0:beta2:*:*:beta:*:*:*

EPSS

Процентиль: 58%
0.00362
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-400

EPSS

Процентиль: 58%
0.00362
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-400