Discourse is an open source discussion platform. In affected versions a malicious user can cause a regular expression denial of service using a carefully crafted git URL. This issue is patched in the latest stable, beta and tests-passed versions of Discourse. Users are advised to upgrade. There are no known workarounds for this issue.
2023-02-08T20:15:25.100
2024-11-21T07:49:14.367
Modified
CVSSv3.1: 6.5 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | discourse | discourse | < 3.0.1 | Yes |
| Application | discourse | discourse | 3.1.0 | Yes |