// For flags

CVE-2022-23641

Denial of Service in Discourse

Severity Score

6.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Discourse is an open source discussion platform. In versions prior to 2.8.1 in the `stable` branch, 2.9.0.beta2 in the `beta` branch, and 2.9.0.beta2 in the `tests-passed` branch, users can trigger a Denial of Service attack by posting a streaming URL. Parsing Oneboxes in the background job trigger an infinite loop, which cause memory leaks. This issue is patched in version 2.8.1 of the `stable` branch, 2.9.0.beta2 of the `beta` branch, and 2.9.0.beta2 of the `tests-passed` branch. As a workaround, disable onebox in admin panel completely or specify allow list of domains that will be oneboxed.

Discourse es una plataforma de debate de código abierto. En las versiones anteriores a 2.8.1 en la rama "stable", versión 2.9.0.beta2 en la rama "beta" y versión 2.9.0.beta2 en la rama "tests-passed", los usuarios pueden desencadenar un ataque de Denegación de Servicio al publicar una URL en streaming. El análisis de Oneboxes en el trabajo de fondo desencadena un bucle infinito, que causa pérdidas de memoria. Este problema está parcheado en versión 2.8.1 de la rama "stable", en versión 2.9.0.beta2 de la rama "beta" y en versión 2.9.0.beta2 de la rama "tests-passed". Como medida de mitigación, deshabilite por completo el onebox en el panel de administración o especifique la lista de dominios permitidos para el oneboxing

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-01-19 CVE Reserved
  • 2022-02-15 CVE Published
  • 2023-10-07 EPSS Updated
  • 2024-08-03 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Discourse
Search vendor "Discourse"
Discourse
Search vendor "Discourse" for product "Discourse"
< 2.8.1
Search vendor "Discourse" for product "Discourse" and version " < 2.8.1"
-
Affected