← Back

CVE-2024-38360

nvd nist
Published: Jul 15, 2024Modified: Aug 26, 2025

JSON object

Loading...
4.9
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Exploitability: 1.2 / Impact: 3.6
Source: security-advisories@github.com (Secondary)

Description

Discourse is an open source platform for community discussion. In affected versions by creating replacement words with an almost unlimited number of characters, a moderator can reduce the availability of a Discourse instance. This issue has been addressed in stable version 3.2.3 and in current betas. Users are advised to upgrade. Users unable to upgrade may manually remove the long watched words either via SQL or Rails console.

Affected (4)

Products: Discourse: Discourse
1 product
Discourse
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Discourse
Before 3.3.0
Before 3.3.2
Version 3.3.0 beta1
Version 3.3.0 beta2

Timeline

No history available yet.