CVE-2022-41921: Discourse chat messages should have a maximum character limit
Discourse is an open-source discussion platform. Prior to version 2.9.0.beta13, users can post chat messages of an unlimited length, which can cause a denial of service for other users when posting huge amounts of text. Users should upgrade to version 2.9.0.beta13, where a limit has been introduced. No known workarounds are available.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Discourseto a version that resolves this vulnerability.Fixed in 2.9.0.beta13
Event History
Frequently Asked Questions
What is the severity of CVE-2022-41921?
CVE-2022-41921 has a moderate severity rating as it can lead to a denial of service by allowing users to post excessively long messages.
How do I fix CVE-2022-41921?
To fix CVE-2022-41921, users should upgrade to Discourse version 2.9.0.beta13 or later, which implements a limit on message length.
Which versions of Discourse are affected by CVE-2022-41921?
CVE-2022-41921 affects all versions of Discourse prior to 2.9.0.beta13.
What impact does CVE-2022-41921 have on users?
CVE-2022-41921 may cause service disruptions for users when someone posts extremely long messages, potentially overwhelming the platform.
Is there a workaround for CVE-2022-41921 before upgrading?
There are no suggested workarounds for CVE-2022-41921 other than upgrading to the patched version.