Skip to content

Chat drafts should have a maximum character limit and the number of loaded drafts should be limited

Low
pmusaraj published GHSA-pwj4-rf62-p224 Jan 25, 2023

Package

Discourse - chat (Discourse)

Affected versions

beta < 3.1.0.beta1; tests-passed < 3.1.0.beta1

Patched versions

beta >= 3.1.0.beta1; tests-passed >= 3.1.0.beta1

Description

Impact

Users can create chat drafts of an unlimited length, which can cause a denial of service by generating an excessive load on the server. Additionally an unlimited number of drafts were loaded when loading the user.

Patches

Users should upgrade to the latest version where a limit has been introduced.

Workarounds

No workarounds available.

Severity

Low
3.5
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
Low
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L

CVE ID

CVE-2023-22740

Weaknesses

No CWEs