Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-41042: DoS via remote theme assets

Discourse is an open-source discussion platform. Prior to version 3.1.1 of the stable branch and version 3.2.0.beta1 of the beta and tests-passed branches, importing a remote theme loads their assets into memory without enforcing limits for file size or number of files. The issue is patched in version 3.1.1 of the stable branch and version 3.2.0.beta1 of the beta and tests-passed branches. There are no known workarounds.

CVE

Moderate

jomaxro published GHSA-2fq5-x3mm-v254

Sep 12, 2023

Package

Discourse (Discourse)

Affected versions

stable <= 3.1.0; beta <= 3.1.0.beta8; tests-passed <= 3.1.0.beta8

Patched versions

stable >= 3.1.1; beta >= 3.2.0.beta1; tests-passed >= 3.2.0.beta1

Description

Impact

Importing a remote theme loads their assets into memory without enforcing limits for file size or number of files.

Patches

This issue is patched in the latest stable, beta and tests-passed versions of Discourse.

Workarounds

None.

Severity

CVSS base metrics

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda