Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-24808

Опубликовано: 26 мар. 2025
Источник: nvd
CVSS3: 4.3
CVSS3: 3.1
EPSS Низкий

Описание

Discourse is an open-source discussion platform. Prior to versions 3.3.4 on the stable branch and 3.4.0.beta5 on the beta branch, someone who is about to reach the limit of users in a group DM may send requests to add new users in parallel. The requests might all go through ignoring the limit due to a race condition. The patch in versions 3.3.4 and 3.4.0.beta5 uses the lock step in service to wrap part of the add_users_to_channel service inside a distributed lock/mutex in order to avoid the race condition.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:discourse:discourse:*:*:*:*:stable:*:*:*
Версия до 3.3.3 (исключая)
cpe:2.3:a:discourse:discourse:*:*:*:*:beta:*:*:*
Версия до 3.4.0 (исключая)
cpe:2.3:a:discourse:discourse:3.4.0:beta1:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:3.4.0:beta2:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:3.4.0:beta3:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:3.4.0:beta4:*:*:beta:*:*:*

EPSS

Процентиль: 29%
0.00103
Низкий

4.3 Medium

CVSS3

3.1 Low

CVSS3

Дефекты

CWE-362

EPSS

Процентиль: 29%
0.00103
Низкий

4.3 Medium

CVSS3

3.1 Low

CVSS3

Дефекты

CWE-362