CVE-2023-25167 MEDIUM

CVE-2023-25167: Regular expression denial of service via installing themes via git in discourse

Vendor Discourse
Product discourse
Weakness CWE-1333
Published February 8, 2023
Last update March 10, 2025

CVSS base score

6.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

What the vulnerability does

01Description

Discourse is an open source discussion platform. In affected versions a malicious user can cause a regular expression denial of service using a carefully crafted git URL. This issue is patched in the latest stable, beta and tests-passed versions of Discourse. Users are advised to upgrade. There are no known workarounds for this issue.

Key dates

02Disclosure timeline

February 8, 2023 CVE published
March 10, 2025 Record updated