CVE-2024-37299
Discourse vulnerable to DoS via Tag Group
Discourse is an open source discussion platform. Prior to 3.2.5 and 3.3.0.beta5, crafting requests to submit very long tag group names can reduce the availability of a Discourse instance. This vulnerability is fixed in 3.2.5 and 3.3.0.beta5.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Affected products
discourse · discourseWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →