CVE-2024-37299
30.07.2024, 15:15
Discourse is an open source discussion platform. Prior to 3.2.5 and 3.3.0.beta5, crafting requests to submit very long tag group names can reduce the availability of a Discourse instance. This vulnerability is fixed in 3.2.5 and 3.3.0.beta5.Enginsight
Vendor | Product | Version |
---|---|---|
discourse | discourse | 𝑥 < 3.2.5 |
discourse | discourse | 3.3.0:beta1 |
discourse | discourse | 3.3.0:beta2 |
discourse | discourse | 3.3.0:beta3 |
discourse | discourse | 3.3.0:beta4 |
𝑥
= Vulnerable software versions
References