CVE-2023-22739

Source
https://cve.org/CVERecord?id=CVE-2023-22739
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-22739.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-22739
Aliases
Published
2023-01-26T08:45:37Z
Modified
2026-09-29T11:46:47Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Discourse subject to Allocation of Resources Without Limits or Throttling
Details

Discourse is an open source platform for community discussion. Versions prior to 3.0.1 (stable), 3.1.0.beta2 (beta), and 3.1.0.beta2 (tests-passed) are subject to Allocation of Resources Without Limits or Throttling. As there is no limit on data contained in a draft, a malicious user can create an arbitrarily large draft, forcing the instance to a crawl. This issue is patched in versions 3.0.1 (stable), 3.1.0.beta2 (beta), and 3.1.0.beta2 (tests-passed). There are no workarounds.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-770"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/22xxx/CVE-2023-22739.json"
}
References

Affected packages

Git / github.com/discourse/discourse

Affected ranges

Type
GIT
Repo
https://github.com/discourse/discourse
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "stable < 3.0.1"
        },
        {
            "last_affected":  "stable < 3.0.1"
        },
        {
            "introduced":  "beta < 3.1.0.beta2"
        },
        {
            "last_affected":  "beta < 3.1.0.beta2"
        },
        {
            "introduced":  "tests-passed <3.1.0.beta2"
        },
        {
            "last_affected":  "tests-passed <3.1.0.beta2"
        }
    ],
    "source":  "AFFECTED_FIELD"
}

Affected versions

beta < 3.*
beta < 3.1.0.beta2
stable < 3.*
stable < 3.0.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-22739.json"