NA

CVE-2023-48297

Published: 12/01/2024 Updated: 25/01/2024
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Discourse is a platform for community discussion. The message serializer uses the full list of expanded chat mentions (@all and @here) which can lead to a very long array of users. This issue was patched in versions 3.1.4 and beta 3.2.0.beta5.

Vulnerable Product Search on Vulmon Subscribe to Product

discourse discourse 3.2.0

discourse discourse