CVE-2023-28107

MEDIUM

Discourse < 3.0.1 - Resource Allocation Without Limits

Title source: rule
STIX 2.1

Description

Discourse is an open-source discussion platform. Prior to version 3.0.2 of the `stable` branch and version 3.1.0.beta3 of the `beta` and `tests-passed` branches, a user logged as an administrator can request backups multiple times, which will eat up all the connections to the DB. If this is done on a site using multisite, then it can affect the whole cluster. The vulnerability is patched in version 3.0.2 of the `stable` branch and version 3.1.0.beta3 of the `beta` and `tests-passed` branches. There are no known workarounds.

Scores

CVSS v3 4.5
EPSS 0.0098
EPSS Percentile 76.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-770
Status published
Products (3)
discourse/discourse 3.1.0 beta1 (2 CPE variants)
discourse/discourse < 3.0.1
discourse/discourse < 3.1.0
Published Mar 17, 2023
Tracked Since Feb 18, 2026