CVE-2024-43789
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Oct 7, 2024
Updated: Oct 19, 2024
CWE ID 400
Summary
CVE-2024-43789 impacts Discourse, an open-source community discussion platform. Maliciously crafted posts with a large number of replies can cause the platform to become unresponsive as the user tries to fetch them all at once. This issue reduces the availability of Discourse instances. Users are strongly advised to upgrade to the latest version to apply the patch. No known workarounds exist for this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Discourse