Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the stable
branch, if a user has been quoted and uses a |
in their full name, they might be able to trigger a bug that generates a lot of duplicate content in all the posts they've been quoted by updating their full name again. Version 3.1.3 of the stable
branch contain a patch for this issue. No known workaround exists, although one can stop the "bleeding" by ensuring users only use alphanumeric characters in their full name field.
{ "cpes": [ "cpe:2.3:a:discourse:discourse:*:*:*:*:stable:*:*:*", "cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*", "cpe:2.3:a:discourse:discourse:*:*:*:*:beta:*:*:*", "cpe:2.3:a:discourse:discourse:3.2.0:beta1:*:*:beta:*:*:*", "cpe:2.3:a:discourse:discourse:3.2.0:beta2:*:*:beta:*:*:*" ], "severity": "Medium" }