CVE-2021-43850: Denial of Service in discourse
Discourse is an open source platform for community discussion. In affected versions admins users can trigger a Denial of Service attack via the /message-bus/diagnostics path. The impact of this vulnerability is greater on multisite Discourse instances (where multiple forums are served from a single application server) where any admin user on any of the forums are able to visit the /message-bus/diagnostics path. The problem has been patched. Please upgrade to 2.8.0.beta10 or 2.7.12. No workarounds for this issue exist.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-43850?
CVE-2021-43850 has the potential to cause a Denial of Service attack, especially impacting multisite Discourse instances.
How do I fix CVE-2021-43850?
To remediate CVE-2021-43850, update Discourse to a version greater than 2.7.12 or use the latest beta release.
Which versions of Discourse are affected by CVE-2021-43850?
Versions of Discourse up to 2.7.12 and certain 2.8.0 beta releases are affected by CVE-2021-43850.
Can CVE-2021-43850 affect multisite Discourse installations?
Yes, CVE-2021-43850 poses a greater risk for multisite Discourse installations.
What specific functionality is exploited in CVE-2021-43850?
CVE-2021-43850 can be exploited via the '/message-bus/_diagnostics' path to trigger a Denial of Service.