Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-36466: Topic Title Validation Skipped When Changing Category

Discourse is an open source discussion platform. When editing a topic, there is a vulnerability that enables a user to bypass the topic title validations for things like title length, number of emojis in title and blank topic titles. The issue is patched in the latest stable, beta and tests-passed version of Discourse.

CVE
#vulnerability

Package

Discourse (Discourse)

Affected versions

stable <= 3.0.4; beta <= 3.1.0.beta5; tests-passed <= 3.1.0.beta5

Patched versions

stable >= 3.0.5; beta >= 3.1.0.beta6; tests-passed >= 3.1.0.beta6

Description

Impact

When editing a topic, there is a vulnerability that enables a user to bypass the topic title validations for things like title length, number of emojis in title and blank topic titles.

Patches

The issue is patched in the latest stable, beta and tests-passed version of Discourse.

Workarounds

None

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda