Discourse is an open source platform for community discussion. In affected versions admins users can trigger a Denial of Service attack via the /message-bus/_diagnostics path. The impact of this vulnerability is greater on multisite Discourse instances (where multiple forums are served from a single application server) where any admin user on any of the forums are able to visit the /message-bus/_diagnostics path. The problem has been patched. Please upgrade to 2.8.0.beta10 or 2.7.12. No workarounds for this issue exist.
| Software | From | Fixed in |
|---|---|---|
| discourse / discourse | 2.8.0-beta1 | 2.8.0-beta1.x |
| discourse / discourse | 2.8.0-beta2 | 2.8.0-beta2.x |
| discourse / discourse | 2.8.0-beta3 | 2.8.0-beta3.x |
| discourse / discourse | 2.8.0-beta4 | 2.8.0-beta4.x |
| discourse / discourse | 2.8.0-beta5 | 2.8.0-beta5.x |
| discourse / discourse | 2.8.0-beta6 | 2.8.0-beta6.x |
| discourse / discourse | 2.8.0-beta7 | 2.8.0-beta7.x |
| discourse / discourse | 2.8.0-beta9 | 2.8.0-beta9.x |
| discourse / discourse | 2.8.0-beta8 | 2.8.0-beta8.x |
| discourse / discourse | - | 2.7.12 |