Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, if a user has been quoted and uses a `|` in their full name, they might be able to trigger a bug that generates a lot of duplicate content in all the posts they've been quoted by updating their full name again. Version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches contain a patch for this issue. No known workaround exists, although one can stop the "bleeding" by ensuring users only use alphanumeric characters in their full name field.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2023-11-10 15:15
Updated : 2023-11-17 18:03
NVD link : CVE-2023-45806
Mitre link : CVE-2023-45806
CVE.ORG link : CVE-2023-45806
JSON object : View
Products Affected
discourse
- discourse
CWE
CWE-1333
Inefficient Regular Expression Complexity