Vulnerability Description
Discourse is an open source discussion platform. When editing a topic, there is a vulnerability that enables a user to bypass the topic title validations for things like title length, number of emojis in title and blank topic titles. The issue is patched in the latest stable, beta and tests-passed version of Discourse.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Discourse | Discourse | < 3.0.5 |
Related Weaknesses (CWE)
References
- https://github.com/discourse/discourse/security/advisories/GHSA-4hjh-wg43-p932Vendor Advisory
- https://github.com/discourse/discourse/security/advisories/GHSA-4hjh-wg43-p932Vendor Advisory
FAQ
What is CVE-2023-36466?
CVE-2023-36466 is a vulnerability with a CVSS score of 3.5 (LOW). Discourse is an open source discussion platform. When editing a topic, there is a vulnerability that enables a user to bypass the topic title validations for things like title length, number of emojis...
How severe is CVE-2023-36466?
CVE-2023-36466 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-36466?
Check the references section above for vendor advisories and patch information. Affected products include: Discourse Discourse.