CVE-2024-21658

MEDIUM

discourse_calendar < 2024-08-28 - Denial of Service via Excessive Region Value Length

Title source: llm
STIX 2.1

Description

discourse-calendar is a discourse plugin which adds the ability to create a dynamic calendar in the first post of a topic. The limit on region value length is too generous. This allows a malicious actor to cause a Discourse instance to use excessive bandwidth and disk space. This issue has been patched in main the main branch. There are no workarounds for this vulnerability. Please upgrade as soon as possible.

References (1)

Core 1

Scores

CVSS v3 4.3
EPSS 0.0021
EPSS Percentile 43.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-770 CWE-400
Status published
Products (1)
discourse/discourse_calendar < 2024-08-28
Published Aug 30, 2024
Tracked Since Feb 18, 2026