CVE-2023-48297: Discourse vulnerable to unlimited mentioned users in message serializer
Discourse is a platform for community discussion. The message serializer uses the full list of expanded chat mentions (@all and @here) which can lead to a very long array of users. This issue was patched in versions 3.1.4 and beta 3.2.0.beta5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-48297?
CVE-2023-48297 has a medium severity rating due to its potential to create excessively long arrays of users.
How do I fix CVE-2023-48297?
To fix CVE-2023-48297, upgrade to version 3.1.4 or later, or to beta version 3.2.0.beta5 or later.
What software does CVE-2023-48297 affect?
CVE-2023-48297 affects Discourse versions prior to 3.1.4 and beta versions before 3.2.0.beta5.
What does CVE-2023-48297 involve?
CVE-2023-48297 involves the message serializer in Discourse which can potentially handle too many expanded chat mentions.
Is there a known exploit for CVE-2023-48297?
As of now, there are no publicly known exploits for CVE-2023-48297, but it's recommended to apply patches promptly.