CVE-2021-43850

MEDIUM

Discourse <2.8.0.beta10, <2.7.12 - DoS

Title source: llm
STIX 2.1

Description

Discourse is an open source platform for community discussion. In affected versions admins users can trigger a Denial of Service attack via the `/message-bus/_diagnostics` path. The impact of this vulnerability is greater on multisite Discourse instances (where multiple forums are served from a single application server) where any admin user on any of the forums are able to visit the `/message-bus/_diagnostics` path. The problem has been patched. Please upgrade to 2.8.0.beta10 or 2.7.12. No workarounds for this issue exist.

References (2)

Core 2
Core References
Exploit, Third Party Advisory x_refsource_confirm
https://github.com/discourse/discourse/security/advisories/GHSA-59jr-pj65-qmvr

Scores

CVSS v3 6.8
EPSS 0.0030
EPSS Percentile 53.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (2)
discourse/discourse 2.8.0 beta1 (9 CPE variants)
discourse/discourse < 2.7.12
Published Jan 04, 2022
Tracked Since Feb 18, 2026