Headline
CVE-2023-41042: DoS via remote theme assets
Discourse is an open-source discussion platform. Prior to version 3.1.1 of the stable
branch and version 3.2.0.beta1 of the beta
and tests-passed
branches, importing a remote theme loads their assets into memory without enforcing limits for file size or number of files. The issue is patched in version 3.1.1 of the stable
branch and version 3.2.0.beta1 of the beta
and tests-passed
branches. There are no known workarounds.
Moderate
jomaxro published GHSA-2fq5-x3mm-v254
Sep 12, 2023
Package
Discourse (Discourse)
Affected versions
stable <= 3.1.0; beta <= 3.1.0.beta8; tests-passed <= 3.1.0.beta8
Patched versions
stable >= 3.1.1; beta >= 3.2.0.beta1; tests-passed >= 3.2.0.beta1
Description
Impact
Importing a remote theme loads their assets into memory without enforcing limits for file size or number of files.
Patches
This issue is patched in the latest stable, beta and tests-passed versions of Discourse.
Workarounds
None.
Severity
CVSS base metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H