CVE-2023-48297

HIGH7.5EPSS 0.18%

Discourse vulnerable to unlimited mentioned users in message serializer

Published: 3/6/2024Modified: 10/15/2025
Also known as:GHSA-hf2v-r5xm-8p37BIT-discourse-2023-48297

Description

Discourse is a platform for community discussion. The message serializer uses the full list of expanded chat mentions (@all and @here) which can lead to a very long array of users. This issue was patched in versions 3.1.4 and beta 3.2.0.beta5.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References (2)