DoS via drafts
Package
Discourse
(Discourse)
Affected versions
stable <= 3.1.0; beta <= 3.1.0.beta8; tests-passed <= 3.1.0.beta8
Patched versions
stable >= 3.1.1; beta >= 3.2.0.beta1; tests-passed >= 3.2.0.beta1
Impact
A malicious user can create an unlimited number of drafts with very long draft keys which may end up exhausting the resources on the server.
Patches
This issue is patched in the latest stable, beta and tests-passed versions of Discourse.
Workarounds
None.