First published: Mon Nov 28 2022(Updated: )
Discourse is an open-source discussion platform. Prior to version 2.9.0.beta13, users can post chat messages of an unlimited length, which can cause a denial of service for other users when posting huge amounts of text. Users should upgrade to version 2.9.0.beta13, where a limit has been introduced. No known workarounds are available.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Discourse Discourse | <2.9.0 | |
Discourse Discourse | =2.9.0-beta1 | |
Discourse Discourse | =2.9.0-beta10 | |
Discourse Discourse | =2.9.0-beta11 | |
Discourse Discourse | =2.9.0-beta12 | |
Discourse Discourse | =2.9.0-beta2 | |
Discourse Discourse | =2.9.0-beta3 | |
Discourse Discourse | =2.9.0-beta4 | |
Discourse Discourse | =2.9.0-beta5 | |
Discourse Discourse | =2.9.0-beta6 | |
Discourse Discourse | =2.9.0-beta7 | |
Discourse Discourse | =2.9.0-beta8 | |
Discourse Discourse | =2.9.0-beta9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.