CVE-2023-28107: Discourse vulnerable to multisite DoS by spamming backups
Discourse is an open-source discussion platform. Prior to version 3.0.2 of the stable branch and version 3.1.0.beta3 of the beta and tests-passed branches, a user logged as an administrator can request backups multiple times, which will eat up all the connections to the DB. If this is done on a site using multisite, then it can affect the whole cluster. The vulnerability is patched in version 3.0.2 of the stable branch and version 3.1.0.beta3 of the beta and tests-passed branches. There are no known workarounds.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this Discourse vulnerability?
The vulnerability ID for this Discourse vulnerability is CVE-2023-28107.
What is the severity of CVE-2023-28107?
The severity of CVE-2023-28107 is medium (4.9).
How does this vulnerability affect Discourse?
This vulnerability affects Discourse versions prior to 3.0.2 of the `stable` branch and version 3.1.0.beta3 of the `beta` and `tests-passed` branches.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by requesting backups multiple times as an administrator, which will consume all the connections to the database.
Are there any available fixes for CVE-2023-28107?
Yes, Discourse has released fixes for CVE-2023-28107. It is recommended to update to version 3.0.2 of the `stable` branch or version 3.1.0.beta3 of the `beta` and `tests-passed` branches.