Exploit Report

Computer Security And Bug Information

CVE-2023-23616

CVECVE-2023-23616
CVE Title
Published Date2023-01-28T00:15Z
Modified Date2023-01-30T14:18Z
CWE TypeCWE-400
DescriptionDiscourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and 3.1.0.beta2 on the `beta` and `tests-passed` branches, when submitting a membership request, there is no character limit for the reason provided with the request. This could potentially allow a user to flood the database with a large amount of data. However it is unlikely this could be used as part of a DoS attack, as the paths reading back the reasons are only available to administrators. Starting in version 3.0.1 on the `stable` branch and 3.1.0.beta2 on the `beta` and `tests-passed` branches, a limit of 280 characters has been introduced for membership requests.
References
By clicking these links you will leave this website. We do not endorse and will not be held accountable for any activity on external sites.
Reference URLhttps://github.com/discourse/discourse/pull/19993
Reference DescriptionMISC https://github.com/discourse/discourse/pull/19993
Reference URLhttps://github.com/discourse/discourse/security/advisories/GHSA-6xff-p329-9pgf
Reference DescriptionCONFIRM https://github.com/discourse/discourse/security/advisories/GHSA-6xff-p329-9pgf
Reference URLhttps://github.com/discourse/discourse/commit/d5745d34c20c31a221039d8913f33064433003ea
Reference DescriptionMISC https://github.com/discourse/discourse/commit/d5745d34c20c31a221039d8913f33064433003ea
Reference URLhttps://github.com/discourse/discourse/commit/3e0cc4a5d9ef44ad902f6985d046ebb32f0a14ee
Reference DescriptionMISC https://github.com/discourse/discourse/commit/3e0cc4a5d9ef44ad902f6985d046ebb32f0a14ee
Sources NIST MITRE
Note
  • No CVSS data for this CVE

This site's data is aggregated programmatically and provided "as is" without any representations or warranties, express or implied. Exploit.report is not affiliated with the The MITRE Corporation, U.S. Department of Homeland Security (DHS), Cybersecurity and Infrastructure Security Agency (CISA), or US government in any way. CVE and the CVE logo are registered trademarks of The MITRE Corporation

© 2022 Exploit.Report | Data | Contact | Privacy Policy | Articles