CVE-2023-25167: Regular expression denial of service via installing themes via git in discourse
Discourse is an open source discussion platform. In affected versions a malicious user can cause a regular expression denial of service using a carefully crafted git URL. This issue is patched in the latest stable, beta and tests-passed versions of Discourse. Users are advised to upgrade. There are no known workarounds for this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-25167?
CVE-2023-25167 is a vulnerability in Discourse, an open source discussion platform, that allows a malicious user to cause a regular expression denial of service using a carefully crafted git URL.
How severe is CVE-2023-25167?
CVE-2023-25167 has a severity rating of 5.7, which is considered medium.
Which versions of Discourse are affected by CVE-2023-25167?
Discourse versions up to and excluding 3.0.1, as well as 3.1.0-beta1, are affected by CVE-2023-25167.
How can I fix CVE-2023-25167?
It is recommended to upgrade Discourse to the latest stable, beta, or tests-passed versions, which include the fix for CVE-2023-25167.
Where can I find more information about CVE-2023-25167?
You can find more information about CVE-2023-25167 on the Discourse GitHub repository and the Discourse security advisories page.