Headline
CVE-2022-23641: SECURITY: Onebox response timeout and size limit by lis2 · Pull Request #15927 · discourse/discourse
Discourse is an open source discussion platform. In versions prior to 2.8.1 in the stable
branch, 2.9.0.beta2 in the beta
branch, and 2.9.0.beta2 in the tests-passed
branch, users can trigger a Denial of Service attack by posting a streaming URL. Parsing Oneboxes in the background job trigger an infinite loop, which cause memory leaks. This issue is patched in version 2.8.1 of the stable
branch, 2.9.0.beta2 of the beta
branch, and 2.9.0.beta2 of the tests-passed
branch. As a workaround, disable onebox in admin panel completely or specify allow list of domains that will be oneboxed.
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
SECURITY: Onebox response timeout and size limit #15927