CVE-2023-36818: Denial of service via User Custom Sidebar Section Unlimited Link Creation in discourse
Discourse is an open source discussion platform. In affected versions a request to create or update custom sidebar section can cause a denial of service. This issue has been patched in commit 52b003d915. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch 52b003d915
Event History
Frequently Asked Questions
What is CVE-2023-36818?
CVE-2023-36818 is a vulnerability in Discourse, an open source discussion platform, that allows a denial of service attack when creating or updating custom sidebar sections.
What is the severity of CVE-2023-36818?
The severity of CVE-2023-36818 is high with a CVSS score of 7.5.
How can I exploit CVE-2023-36818?
We do not provide instructions or support for exploiting vulnerabilities.
How do I fix CVE-2023-36818?
To fix CVE-2023-36818, users are advised to upgrade to the patched version of Discourse, which can be found in the commit 52b003d915.
Are there any workarounds for CVE-2023-36818?
There are no known workarounds for CVE-2023-36818.