CVE-2024-38360

Discourse is an open source platform for community discussion. In affected versions by creating replacement words with an almost unlimited number of characters, a moderator can reduce the availability of a Discourse instance. This issue has been addressed in stable version 3.2.3 and in current betas. Users are advised to upgrade. Users unable to upgrade may manually remove the long watched words either via SQL or Rails console.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:discourse:discourse:*:*:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:*:*:*:*:stable:*:*:*
cpe:2.3:a:discourse:discourse:3.3.0:beta1:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:3.3.0:beta2:*:*:beta:*:*:*

History

No history.

Information

Published : 2024-07-15 20:15

Updated : 2025-08-26 19:13


NVD link : CVE-2024-38360

Mitre link : CVE-2024-38360

CVE.ORG link : CVE-2024-38360


JSON object : View

Products Affected

discourse

  • discourse
CWE
CWE-400

Uncontrolled Resource Consumption