CVE-2024-53851
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2024-53851 is a vulnerability affecting Discourse, an open-source community discussion platform. In vulnerable versions, the endpoint for generating inline oneboxes for URLs fails to implement proper limits, allowing authenticated attackers to submit an excessive number of URLs. This can lead to a denial-of-service condition in certain parts of the application. Discourse has released patches for this issue in the latest stable, beta, and tests-passed versions. It is strongly recommended that users upgrade as soon as possible. Those unable to upgrade should disable the `enable inline onebox on all domains` site setting and remove all entries from the `allowed inline onebox domains` site setting as temporary mitigations.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Discourse