You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository was archived by the owner on Jul 15, 2025. It is now read-only.
pmusaraj
published
GHSA-65f2-9ghp-x8h8Aug 30, 2024
Package
discourse-calendar
Affected versions
n/a
Patched versions
n/a
Description
Impact
The limit on region value length is too generous. This allows a malicious actor to cause a Discourse instance to use excessive bandwidth and disk space.
Patches
The issue is patched in main.
Workarounds
There are no workarounds for this vulnerability. Please upgrade as soon as possible.
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
Learn more on MITRE.
Impact
The limit on region value length is too generous. This allows a malicious actor to cause a Discourse instance to use excessive bandwidth and disk space.
Patches
The issue is patched in main.
Workarounds
There are no workarounds for this vulnerability. Please upgrade as soon as possible.